CVE-2015-7814Improper Restriction of Operations within the Bounds of a Memory Buffer in XEN

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 82.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 30
Latest updateMay 17

Description

Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6.x and earlier allows local domains with partial management control to cause a denial of service (host crash) via vectors involving the destruction of a domain and using XENMEM_decrease_reservation to reduce the memory of the domain.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages3 packages

debiandebian/xen< xen 4.6.0-1 (bookworm)
Debianxen/xen< 4.6.0-1+3
NVDxen/xen4.6.0

🔴Vulnerability Details

2
GHSA
GHSA-99f8-q7r8-wg7x: Race condition in the relinquish_memory function in arch/arm/domain2022-05-17
OSV
CVE-2015-7814: Race condition in the relinquish_memory function in arch/arm/domain2015-10-30

📋Vendor Advisories

2
Red Hat
xen: Race between domain destruction and memory allocation decrease on ARM2015-10-29
Debian
CVE-2015-7814: xen - Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6...2015

💬Community

3
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]2015-10-29
Bugzilla
CVE-2015-7814 xen: Race between domain destruction and memory allocation decrease on ARM2015-10-14
Bugzilla
CVE-2014-7814 CFME: REST API SQL Injection2014-10-27