CVE-2015-2151
published 2015-03-12CVE-2015-2151: The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.57%
43.4th percentile
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.4.1-8 (bookworm) | xen 4.4.1-8 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mp6j-2xjg-wm8g: The x86 emulator in Xen 3
ghsa_unreviewed·2022-05-14
CVE-2015-2151 [HIGH] GHSA-mp6j-2xjg-wm8g: The x86 emulator in Xen 3
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
OSV
CVE-2015-2151: The x86 emulator in Xen 3
osv·2015-03-12·CVSS 7.2
CVE-2015-2151 [HIGH] CVE-2015-2151: The x86 emulator in Xen 3
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
Red Hat
xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)
vendor_redhat·2015-03-10·CVSS 7.2
CVE-2015-2151 [HIGH] xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)
xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
It was found that the Xen hypervisor x86 CPU emulator implementation did not correctly handle certain instructions with segment overrides, potentially resulting in a memory corruption. A malicious guest user could use this flaw to read arbitrary data relating to other guests, cause a denial of service on the host, or potentially escalate their privileges on the host.
Statement: This issue does affect the Xen hypervisor package
Debian
CVE-2015-2151: xen - The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment ove...
vendor_debian·2015·CVSS 7.2
CVE-2015-2151 [HIGH] CVE-2015-2151: xen - The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment ove...
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-8)
bullseye: resolved (fixed in 4.4.1-8)
forky: resolved (fixed in 4.4.1-8)
sid: resolved (fixed in 4.4.1-8)
trixie: resolved (fixed in 4.4.1-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123) [fedora-all]
bugzilla·2015-03-10·CVSS 7.2
CVE-2015-2151 [HIGH] CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123) [fedora-all]
CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)
bugzilla·2015-02-25·CVSS 7.2
CVE-2015-2151 [HIGH] CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)
CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)
ISSUE DESCRIPTION
Instructions with register operands ignore eventual segment overrides
encoded for them. Due to an insufficiently conditional assignment such
a bogus segment override can, however, corrupt a pointer used
subsequently to store the result of the instruction.
IMPACT
A malicious guest might be able to read sensitive data relating to
other guests, or to cause denial of service on the host. Arbitrary code
execution, and therefore privilege escalation, cannot be excluded.
VULNERABLE SYSTEMS
Xen 3.2.x and later are vulnerable.
Xen 3.1.x and earlier have not been inspected.
Only x86 systems are vulnerable. ARM systems are not vulnerable.
MITIGATION
There is no mitigation available for this is
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://support.citrix.com/article/CTX200484http://www.debian.org/security/2015/dsa-3181http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/73015http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031903http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htmhttp://xenbits.xen.org/xsa/advisory-123.htmlhttps://security.gentoo.org/glsa/201604-03http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152483.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152588.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152776.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://support.citrix.com/article/CTX200484http://www.debian.org/security/2015/dsa-3181http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/73015http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031903http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htmhttp://xenbits.xen.org/xsa/advisory-123.htmlhttps://security.gentoo.org/glsa/201604-03
2015-03-12
Published