CVE-2015-7812XEN vulnerability

CWE-2548 documents6 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 77.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 17
Latest updateMay 14

Description

The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages3 packages

debiandebian/xen< xen 4.6.0-1 (bookworm)
Debianxen/xen< 4.6.0-1+3
NVDxen/xen8 versions+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-85xv-69p8-3c8j: The hypercall_create_continuation function in arch/arm/domain2022-05-14
OSV
CVE-2015-7812: The hypercall_create_continuation function in arch/arm/domain2015-11-17

📋Vendor Advisories

2
Red Hat
xen: Host crash when preempting a multicall on ARM2015-10-29
Debian
CVE-2015-7812: xen - The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x thr...2015

💬Community

3
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]2015-10-29
Bugzilla
CVE-2015-7812 xen: Host crash when preempting a multicall on ARM2015-10-14
Bugzilla
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group2014-12-11