CVE-2015-6654
published 2015-09-03CVE-2015-6654: The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.40%
32.8th percentile
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: printk is not rate-limited in xenmem_add_to_physmap_one
vendor_redhat·2015-09-01·CVSS 2.1
CVE-2015-6654 [LOW] xen: printk is not rate-limited in xenmem_add_to_physmap_one
xen: printk is not rate-limited in xenmem_add_to_physmap_one
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.
Statement: Not vulnerable.
This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
This issue does not affect Red Hat Enterprise Linux 6, 7 or any other Red Hat supported product because of the lack of Xen hypervisor support.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-6654: xen - The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and...
vendor_debian·2015·CVSS 2.1
CVE-2015-6654 [LOW] CVE-2015-6654: xen - The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and...
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
GHSA
GHSA-5993-2g85-9fjv: The xenmem_add_to_physmap_one function in arch/arm/mm
ghsa_unreviewed·2022-05-17
CVE-2015-6654 [LOW] GHSA-5993-2g85-9fjv: The xenmem_add_to_physmap_one function in arch/arm/mm
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.
OSV
CVE-2015-6654: The xenmem_add_to_physmap_one function in arch/arm/mm
osv·2015-09-03·CVSS 2.1
CVE-2015-6654 [LOW] CVE-2015-6654: The xenmem_add_to_physmap_one function in arch/arm/mm
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.
No detection rules found.
No public exploits indexed.
2015-09-03
Published