CVE-2015-2751
published 2015-04-01CVE-2015-2751: Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host…
PriorityP427high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.28%
81.2th percentile
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-9 (bookworm) | xen 4.4.1-9 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f69q-gr6m-7j6r: Xen 4
ghsa_unreviewed·2022-05-14
CVE-2015-2751 [HIGH] GHSA-f69q-gr6m-7j6r: Xen 4
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
OSV
CVE-2015-2751: Xen 4
osv·2015-04-01·CVSS 7.1
CVE-2015-2751 [HIGH] CVE-2015-2751: Xen 4
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
Red Hat
xen: certain domctl operations may be abused to lock up the host
vendor_redhat·2015-03-31·CVSS 7.1
CVE-2015-2751 [HIGH] xen: certain domctl operations may be abused to lock up the host
xen: certain domctl operations may be abused to lock up the host
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
Statement: Not vulnerable.
This issue does not affect the kernel-xen packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-2751: xen - Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote ...
vendor_debian·2015·CVSS 7.1
CVE-2015-2751 [HIGH] CVE-2015-2751: xen - Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote ...
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
Scope: local
bookworm: resolved (fixed in 4.4.1-9)
bullseye: resolved (fixed in 4.4.1-9)
forky: resolved (fixed in 4.4.1-9)
sid: resolved (fixed in 4.4.1-9)
trixie: resolved (fixed in 4.4.1-9)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2751 xen: certain domctl operations may be abused to lock up the host [fedora-all]
bugzilla·2015-03-31·CVSS 7.1
CVE-2015-2751 [HIGH] CVE-2015-2751 xen: certain domctl operations may be abused to lock up the host [fedora-all]
CVE-2015-2751 xen: certain domctl operations may be abused to lock up the host [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2015-2751 xen: certain domctl operations may be abused to lock up the host
bugzilla·2015-03-19·CVSS 7.1
CVE-2015-2751 [HIGH] CVE-2015-2751 xen: certain domctl operations may be abused to lock up the host
CVE-2015-2751 xen: certain domctl operations may be abused to lock up the host
ISSUE DESCRIPTION
XSA-77 put the majority of the domctl operations on a list excepting
them from having security advisories issued for them if any effects
their use might have could hamper security. Subsequently some of them
got declared disaggregation safe, but for a small subset this was not
really correct: Their (mis-)use may result in host lockups.
As a result, the potential security benefits of toolstack
disaggregation are not always fully realised.
IMPACT
Domains deliberately given partial management control may be able to
deny service to the entire host.
As a result, in a system designed to enhance security by radically
disaggregating the management, the security may be reduced. But, the
security wi
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.htmlhttp://www.securityfocus.com/bid/73443http://www.securitytracker.com/id/1031997http://xenbits.xen.org/xsa/advisory-127.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.htmlhttp://www.securityfocus.com/bid/73443http://www.securitytracker.com/id/1031997http://xenbits.xen.org/xsa/advisory-127.htmlhttps://security.gentoo.org/glsa/201504-04
2015-04-01
Published