CVE-2015-7812
published 2015-11-17CVE-2015-7812: The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash)…
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.40%
31.6th percentile
The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85xv-69p8-3c8j: The hypercall_create_continuation function in arch/arm/domain
ghsa_unreviewed·2022-05-14
CVE-2015-7812 [MEDIUM] GHSA-85xv-69p8-3c8j: The hypercall_create_continuation function in arch/arm/domain
The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.
OSV
CVE-2015-7812: The hypercall_create_continuation function in arch/arm/domain
osv·2015-11-17·CVSS 4.9
CVE-2015-7812 [MEDIUM] CVE-2015-7812: The hypercall_create_continuation function in arch/arm/domain
The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.
Red Hat
xen: Host crash when preempting a multicall on ARM
vendor_redhat·2015-10-29·CVSS 4.9
CVE-2015-7812 [MEDIUM] xen: Host crash when preempting a multicall on ARM
xen: Host crash when preempting a multicall on ARM
The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.
Mitigation: On systems where the guest kernel is controlled by the host rather than guest administrator, running only kernels which do not make use of multicall functionality will prevent untrusted guest users from exploiting this issue. However untrusted guest administrators can still trigger it unless further steps are taken to prevent them from loading code into the kernel (e.g. by disabling loadable modules etc) or from using other mechanisms which allow them to run code at kernel privilege.
Package: xen (Red Hat Enterpris
Debian
CVE-2015-7812: xen - The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x thr...
vendor_debian·2015·CVSS 4.9
CVE-2015-7812 [MEDIUM] CVE-2015-7812: xen - The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x thr...
The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
bugzilla·2015-10-29·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2015-7812 xen: Host crash when preempting a multicall on ARM
bugzilla·2015-10-14·CVSS 4.9
CVE-2015-7812 [MEDIUM] CVE-2015-7812 xen: Host crash when preempting a multicall on ARM
CVE-2015-7812 xen: Host crash when preempting a multicall on ARM
A vulnerability allowing malicious geust to crash the host was found. Early versions of Xen on ARM did not support "multicall" functionality (the ability to perform multiple operations via a single hypercall) and therefore stubbed out the functionality needed to support preemption of multicalls in a manner which crashed the host. When multicall support was subsequently added these stubs were not replaced with the correct functionality and therefore exposed to guests a code path which crashes the host. Any guest can issue a preemptable hypercall via the multicall interface to exploit this vulnerability. Both 32- and 64-bit ARM systems are vulnerable from Xen 4.4 onward.
Mitigation:
On systems where the guest kernel is contr
Bugzilla
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
bugzilla·2014-12-11·CVSS 3.5
CVE-2014-7812 [LOW] CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
Mickaël Gallier reports:
There are several stored XSS vulnerabilities in various fields in Satellite
server, they can be exploited by using the REST API to send XML data
containing malformed data.
One of these is in the system-group handling. Please see CVE-014-7811 for
the other vulnerabilities.
Discussion:
Acknowledgement:
Red Hat would like to thank Mickaël Gallier for reporting this issue.
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
---
This issue has been addressed in the following products:
Red Hat Satellite Server v 5.7
Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://www.debian.org/security/2015/dsa-3414http://www.securitytracker.com/id/1034031http://xenbits.xen.org/xsa/advisory-145.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://www.debian.org/security/2015/dsa-3414http://www.securitytracker.com/id/1034031http://xenbits.xen.org/xsa/advisory-145.htmlhttps://security.gentoo.org/glsa/201604-03
2015-11-17
Published