CVE-2015-4163
published 2015-06-15CVE-2015-4163: GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.44%
35.5th percentile
GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: GNTTABOP_swap_grant_ref operation misbehavior (xsa-134)
vendor_redhat·2015-06-11·CVSS 4.9
CVE-2015-4163 [MEDIUM] CWE-476 xen: GNTTABOP_swap_grant_ref operation misbehavior (xsa-134)
xen: GNTTABOP_swap_grant_ref operation misbehavior (xsa-134)
GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-4163: xen - GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table op...
vendor_debian·2015·CVSS 4.9
CVE-2015-4163 [MEDIUM] CVE-2015-4163: xen - GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table op...
GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
GHSA
GHSA-586c-2349-hf65: GNTTABOP_swap_grant_ref in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2015-4163 [MEDIUM] GHSA-586c-2349-hf65: GNTTABOP_swap_grant_ref in Xen 4
GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version.
OSV
CVE-2015-4163: GNTTABOP_swap_grant_ref in Xen 4
osv·2015-06-15·CVSS 4.9
CVE-2015-4163 [MEDIUM] CVE-2015-4163: GNTTABOP_swap_grant_ref in Xen 4
GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/75141http://www.securitytracker.com/id/1032568http://xenbits.xen.org/xsa/advisory-134.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/75141http://www.securitytracker.com/id/1032568http://xenbits.xen.org/xsa/advisory-134.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006
2015-06-15
Published