CVE-2015-2752
published 2015-04-01CVE-2015-2752: The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain…
PriorityP417medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.45%
36.6th percentile
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-9 (bookworm) | xen 4.4.1-9 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
| xen | xen | >= 0 < 4.4.1-9 | 4.4.1-9 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rf4p-xq4w-3f34: The XEN_DOMCTL_memory_mapping hypercall in Xen 3
ghsa_unreviewed·2022-05-14
CVE-2015-2752 [MEDIUM] CWE-20 GHSA-rf4p-xq4w-3f34: The XEN_DOMCTL_memory_mapping hypercall in Xen 3
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
OSV
CVE-2015-2752: The XEN_DOMCTL_memory_mapping hypercall in Xen 3
osv·2015-04-01·CVSS 4.9
CVE-2015-2752 [MEDIUM] CVE-2015-2752: The XEN_DOMCTL_memory_mapping hypercall in Xen 3
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Red Hat
xen: long latency MMIO mapping operations are not preemptible (xsa125)
vendor_redhat·2015-03-31·CVSS 4.9
CVE-2015-2752 [MEDIUM] CWE-400 xen: long latency MMIO mapping operations are not preemptible (xsa125)
xen: long latency MMIO mapping operations are not preemptible (xsa125)
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Statement: This issue dos affect the kernel-xen packages as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
P
Debian
CVE-2015-2752: xen - The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a...
vendor_debian·2015·CVSS 4.9
CVE-2015-2752 [MEDIUM] CVE-2015-2752: xen - The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a...
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Scope: local
bookworm: resolved (fixed in 4.4.1-9)
bullseye: resolved (fixed in 4.4.1-9)
forky: resolved (fixed in 4.4.1-9)
sid: resolved (fixed in 4.4.1-9)
trixie: resolved (fixed in 4.4.1-9)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2752 xen: long latency MMIO mapping operations are not preemptible (xsa125) [fedora-all]
bugzilla·2015-03-31·CVSS 4.9
CVE-2015-2752 [MEDIUM] CVE-2015-2752 xen: long latency MMIO mapping operations are not preemptible (xsa125) [fedora-all]
CVE-2015-2752 xen: long latency MMIO mapping operations are not preemptible (xsa125) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2015-2752 xen: long latency MMIO mapping operations are not preemptible (xsa125)
bugzilla·2015-03-19·CVSS 4.9
CVE-2015-2752 [MEDIUM] CVE-2015-2752 xen: long latency MMIO mapping operations are not preemptible (xsa125)
CVE-2015-2752 xen: long latency MMIO mapping operations are not preemptible (xsa125)
ISSUE DESCRIPTION
The XEN_DOMCTL_memory_mapping hypercall allows long running operations
without implementing preemption.
This hypercall is used by the device model as part of the emulation
associated with configuration of PCI devices passed through to HVM
guests and is therefore indirectly exposed to those guests.
This can cause a physical CPU to become busy for a significant period,
leading to a host denial of service in some cases.
If a host denial of service is not triggered then it may instead be
possible to deny service to the domain running the device model,
e.g. domain 0.
This hypercall is also exposed more generally to all
toolstacks. However the uses of it in libxl based toolstacks are not
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.htmlhttp://www.securityfocus.com/bid/73448http://www.securitytracker.com/id/1031994http://xenbits.xen.org/xsa/advisory-125.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.htmlhttp://www.securityfocus.com/bid/73448http://www.securitytracker.com/id/1031994http://xenbits.xen.org/xsa/advisory-125.htmlhttps://security.gentoo.org/glsa/201504-04
2015-04-01
Published