CVE-2015-0361
published 2015-01-07CVE-2015-0361: Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.51%
83.0th percentile
Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-7 (bookworm) | xen 4.4.1-7 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-7 | 4.4.1-7 |
| xen | xen | >= 0 < 4.4.1-7 | 4.4.1-7 |
| xen | xen | >= 0 < 4.4.1-7 | 4.4.1-7 |
| xen | xen | >= 0 < 4.4.1-7 | 4.4.1-7 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f69m-xh7g-gr6j: Use-after-free vulnerability in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2015-0361 [HIGH] GHSA-f69m-xh7g-gr6j: Use-after-free vulnerability in Xen 4
Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown.
OSV
CVE-2015-0361: Use-after-free vulnerability in Xen 4
osv·2015-01-07·CVSS 7.8
CVE-2015-0361 [HIGH] CVE-2015-0361: Use-after-free vulnerability in Xen 4
Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown.
Red Hat
kernel: xen crash due to use after free on hvm guest teardown (xsa116)
vendor_redhat·2015-01-06·CVSS 7.8
CVE-2015-0361 [HIGH] CWE-416 kernel: xen crash due to use after free on hvm guest teardown (xsa116)
kernel: xen crash due to use after free on hvm guest teardown (xsa116)
Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown.
Statement: Not vulnerable.
This issue does not affect the kernel-xen packages as shipped with Red Hat Enterprise Linux 5.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-0361: xen - Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domain...
vendor_debian·2015·CVSS 7.8
CVE-2015-0361 [HIGH] CVE-2015-0361: xen - Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domain...
Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown.
Scope: local
bookworm: resolved (fixed in 4.4.1-7)
bullseye: resolved (fixed in 4.4.1-7)
forky: resolved (fixed in 4.4.1-7)
sid: resolved (fixed in 4.4.1-7)
trixie: resolved (fixed in 4.4.1-7)
No detection rules found.
No public exploits indexed.
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
Bugzilla
CVE-2015-0361 xen: kernel: xen crash due to use after free on hvm guest teardown (xsa116) [fedora-all]
bugzilla·2015-01-06·CVSS 7.8
CVE-2015-0361 [HIGH] CVE-2015-0361 xen: kernel: xen crash due to use after free on hvm guest teardown (xsa116) [fedora-all]
CVE-2015-0361 xen: kernel: xen crash due to use after free on hvm guest teardown (xsa116) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2015-0361 kernel: xen crash due to use after free on hvm guest teardown (xsa116)
bugzilla·2014-12-19·CVSS 7.8
CVE-2015-0361 [HIGH] CVE-2015-0361 kernel: xen crash due to use after free on hvm guest teardown (xsa116)
CVE-2015-0361 kernel: xen crash due to use after free on hvm guest teardown (xsa116)
Xen Security Advisory XSA-116
xen crash due to use after free on hvm guest teardown
ISSUE DESCRIPTION
Certain data accessible (via hypercalls) by the domain controlling the
execution of a HVM domain is being freed prematurely, leading to the
respective memory regions to possibly be read from and written to in
ways unexpected by their new owner(s).
IMPACT
Malicious or buggy stub domain kernels or tool stacks otherwise living
outside of Domain0 can mount a denial of service attack which, if
successful, can affect the whole system.
Only domains controlling HVM guests can exploit this vulnerability.
(This includes domains providing hardware emulation services to HVM
guests.)
VULNERABLE SYSTEMS
Xen ver
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148103.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148241.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://www.securityfocus.com/bid/71882http://www.securitytracker.com/id/1031498http://xenbits.xen.org/xsa/advisory-116.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148103.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148241.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://www.securityfocus.com/bid/71882http://www.securitytracker.com/id/1031498http://xenbits.xen.org/xsa/advisory-116.htmlhttps://security.gentoo.org/glsa/201504-04
2015-01-07
Published