CVE-2015-7835
published 2015-10-30CVE-2015-7835: The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.43%
34.6th percentile
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Uncontrolled creation of large page mappings by PV guests on x86
vendor_redhat·2015-10-29·CVSS 7.2
CVE-2015-7835 [HIGH] xen: Uncontrolled creation of large page mappings by PV guests on x86
xen: Uncontrolled creation of large page mappings by PV guests on x86
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Mitigation: Running only HVM guests will avoid this vulnerability. On systems where the guest kernel is controlled by the host rather than guest administrator, running only kernels which do not call these hypercalls will also prevent untrusted guest users from exploiting this issue. However untrusted guest administrators can still trigger it unless further steps are taken to prevent them from loading code into the kernel (e.g. by disabling loadable modules etc) or from using other mechanisms which allow t
Debian
CVE-2015-7835: xen - The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not pro...
vendor_debian·2015·CVSS 7.2
CVE-2015-7835 [HIGH] CVE-2015-7835: xen - The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not pro...
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
GHSA
GHSA-4rfc-hjfx-gw3f: The mod_l2_entry function in arch/x86/mm
ghsa_unreviewed·2022-05-14
CVE-2015-7835 [HIGH] CWE-20 GHSA-4rfc-hjfx-gw3f: The mod_l2_entry function in arch/x86/mm
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
OSV
CVE-2015-7835: The mod_l2_entry function in arch/x86/mm
osv·2015-10-30·CVSS 7.2
CVE-2015-7835 [HIGH] CVE-2015-7835: The mod_l2_entry function in arch/x86/mm
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
bugzilla·2015-10-29·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2015-7835 xen: Uncontrolled creation of large page mappings by PV guests on x86
bugzilla·2015-10-15·CVSS 7.2
CVE-2015-7835 [HIGH] CVE-2015-7835 xen: Uncontrolled creation of large page mappings by PV guests on x86
CVE-2015-7835 xen: Uncontrolled creation of large page mappings by PV guests on x86
A vulnerability in xen allowing malicious PV guest administrators to escalate privilege, so as to control the whole system, was found.
The code to validate level 2 page table entries is bypassed when certain conditions are satisfied. This means that a PV guest can create writeable mappings using super page mappings. Such writeable mappings can violate Xen intended invariants for pages which Xen is supposed to keep read-only. This is possible even if the "allowsuperpage" command line option is not used.
Xen 3.4 and onward on x86 (both 32 and 64 bit) systems are vulnerable. Only PV guests can exploit the vulnerability.
Mitigation:
Running only HVM guests will avoid this vulnerability. On systems where th
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00063.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3390http://www.securityfocus.com/bid/77366http://www.securitytracker.com/id/1034032http://xenbits.xen.org/xsa/advisory-148.htmlhttps://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-022-2015.txthttps://security.gentoo.org/glsa/201604-03http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00063.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3390http://www.securityfocus.com/bid/77366http://www.securitytracker.com/id/1034032http://xenbits.xen.org/xsa/advisory-148.htmlhttps://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-022-2015.txthttps://security.gentoo.org/glsa/201604-03
2015-10-30
Published