CVE-2015-7971

low
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in the do_xenoprof_op function in common/xenoprof.c, or (2) HYPERVISOR_xenpmu_op hypercalls, which are not properly handled in the do_xenpmu_op function in arch/x86/cpu/vpmu.c.

References

http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.html

http://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html

http://support.citrix.com/article/CTX202404

http://www.debian.org/security/2015/dsa-3414

http://www.securityfocus.com/bid/77363

http://www.securitytracker.com/id/1034035

http://xenbits.xen.org/xsa/advisory-152.html

https://security.gentoo.org/glsa/201604-03

Details

Source: MITRE

Published: 2015-10-30

Updated: 2018-10-30

Type: CWE-19

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
140019OracleVM 3.4 : xen (OVMSA-2020-0039) (Bunker Buster) (Foreshadow) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (Meltdown) (POODLE) (Spectre)NessusOracleVM Local Security Checks
critical
111992OracleVM 3.4 : xen (OVMSA-2018-0248) (Bunker Buster) (Foreshadow) (Meltdown) (POODLE) (Spectre)NessusOracleVM Local Security Checks
critical
91756OracleVM 3.2 : xen (OVMSA-2016-0081)NessusOracleVM Local Security Checks
high
91198Debian DLA-479-1 : xen security updateNessusDebian Local Security Checks
high
90380GLSA-201604-03 : Xen: Multiple vulnerabilities (Venom)NessusGentoo Local Security Checks
critical
89723SUSE SLES10 Security Update : Xen (SUSE-SU-2016:0658-1)NessusSuSE Local Security Checks
critical
89359Fedora 23 : xen-4.5.1-14.fc23 (2015-a931b02be2)NessusFedora Local Security Checks
high
89278Fedora 22 : xen-4.5.1-14.fc22 (2015-6f6b79efe2)NessusFedora Local Security Checks
high
89177Fedora 21 : xen-4.4.3-7.fc21 (2015-242be2c240)NessusFedora Local Security Checks
high
87650SUSE SLED11 / SLES11 Security Update : xen (SUSE-SU-2015:2338-1)NessusSuSE Local Security Checks
high
87591SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2015:2328-1)NessusSuSE Local Security Checks
high
87590SUSE SLED11 / SLES11 Security Update : xen (SUSE-SU-2015:2326-1)NessusSuSE Local Security Checks
high
87528SUSE SLES11 Security Update : xen (SUSE-SU-2015:2306-1)NessusSuSE Local Security Checks
high
87288Debian DSA-3414-1 : xen - security updateNessusDebian Local Security Checks
medium
86961openSUSE Security Update : xen (openSUSE-2015-730)NessusSuSE Local Security Checks
high
86909openSUSE Security Update : xen (openSUSE-2015-750)NessusSuSE Local Security Checks
medium
86865SUSE SLES11 Security Update : xen (SUSE-SU-2015:1952-1)NessusSuSE Local Security Checks
medium
86863openSUSE Security Update : xen (openSUSE-2015-729)NessusSuSE Local Security Checks
medium
86841FreeBSD : xen-kernel -- some pmu and profiling hypercalls log without rate limiting (e4848ca4-8820-11e5-ab94-002590263bf5)NessusFreeBSD Local Security Checks
low
86802OracleVM 3.2 : xen (OVMSA-2015-0143)NessusOracleVM Local Security Checks
high
86756SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2015:1908-1)NessusSuSE Local Security Checks
medium
86753SUSE SLED11 / SLES11 Security Update : xen (SUSE-SU-2015:1894-1)NessusSuSE Local Security Checks
medium
86704SUSE SLED11 / SLES11 Security Update : xen (SUSE-SU-2015:1853-1)NessusSuSE Local Security Checks
medium
86670OracleVM 3.2 : xen (OVMSA-2015-0142)NessusOracleVM Local Security Checks
high
86669OracleVM 3.3 : xen (OVMSA-2015-0141)NessusOracleVM Local Security Checks
high