CVE-2015-4164
published 2015-06-15CVE-2015-4164: The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.44%
35.4th percentile
The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of service (large loop and system hang) via a hypercall_iret call with EFLAGS.VM set.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: iret hypercall handler vulnerability (xsa-136)
vendor_redhat·2015-06-11·CVSS 4.9
CVE-2015-4164 [MEDIUM] xen: iret hypercall handler vulnerability (xsa-136)
xen: iret hypercall handler vulnerability (xsa-136)
The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of service (large loop and system hang) via a hypercall_iret call with EFLAGS.VM set.
Statement: This issue does affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: xen (Red Hat Enterprise Linux 5) -
Debian
CVE-2015-4164: xen - The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a...
vendor_debian·2015·CVSS 4.9
CVE-2015-4164 [MEDIUM] CVE-2015-4164: xen - The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a...
The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of service (large loop and system hang) via a hypercall_iret call with EFLAGS.VM set.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
GHSA
GHSA-jg3g-vx8c-2j78: The compat_iret function in Xen 3
ghsa_unreviewed·2022-05-14
CVE-2015-4164 [MEDIUM] GHSA-jg3g-vx8c-2j78: The compat_iret function in Xen 3
The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of service (large loop and system hang) via a hypercall_iret call with EFLAGS.VM set.
OSV
CVE-2015-4164: The compat_iret function in Xen 3
osv·2015-06-15·CVSS 4.9
CVE-2015-4164 [MEDIUM] CVE-2015-4164: The compat_iret function in Xen 3
The compat_iret function in Xen 3.1 through 4.5 iterates the wrong way through a loop, which allows local 32-bit PV guest administrators to cause a denial of service (large loop and system hang) via a hypercall_iret call with EFLAGS.VM set.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/75149http://www.securitytracker.com/id/1032569http://xenbits.xen.org/xsa/advisory-136.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/75149http://www.securitytracker.com/id/1032569http://xenbits.xen.org/xsa/advisory-136.htmlhttps://security.gentoo.org/glsa/201604-03
2015-06-15
Published