CVE-2015-7969
published 2015-10-30CVE-2015-7969: Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.44%
35.4th percentile
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fpcv-vm34-hph7: Multiple memory leaks in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2015-7969 [MEDIUM] GHSA-fpcv-vm34-hph7: Multiple memory leaks in Xen 4
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
OSV
CVE-2015-7969: Multiple memory leaks in Xen 4
osv·2015-10-30·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969: Multiple memory leaks in Xen 4
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
Red Hat
xen: leak of main per-domain vcpu pointer array
vendor_redhat·2015-10-29·CVSS 4.9
CVE-2015-7969 [MEDIUM] xen: leak of main per-domain vcpu pointer array
xen: leak of main per-domain vcpu pointer array
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
Mitigation: The leak is small. Preventing the creation of large numbers of new domains, and limiting the number of times an existing domain can be rebooted, can reduce the impact of this vulnerability. Switching from disaggregated to a non-disaggregated operation does NOT mitigate the XEN_DOMCTL_max_vcpus vulnerability. Rather,
Debian
CVE-2015-7969: xen - Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators ...
vendor_debian·2015·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969: xen - Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators ...
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
bugzilla·2015-10-29·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
xen: Leak of per-domain profiling-related vcpu pointer array on x86
bugzilla·2015-10-16
[MEDIUM] xen: Leak of per-domain profiling-related vcpu pointer array on x86
xen: Leak of per-domain profiling-related vcpu pointer array on x86
A domain's xenoprofile state contains an array of per-vcpu information, which is allocated once in the lifetime of a domain in response to that domain using the XENOPROF_get_buffer hypercall on itself or by a domain with the privilege to profile a target domain using the XENOPROF_set_passive hypercall. This array is leaked on domain teardown. This memory leak could over time exhaust the host's memory.
The following parties can mount a denial of service attack affecting the whole system:
- A malicious guest administrator via XENOPROF_get_buffer.
- A domain given suitable privilege over another domain via XENOPROF_set_passive (this would usually be a domain being used to profile another domain, eg with the xenoprof tool).
Bugzilla
CVE-2015-7969 xen: leak of main per-domain vcpu pointer array
bugzilla·2015-10-16·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969 xen: leak of main per-domain vcpu pointer array
CVE-2015-7969 xen: leak of main per-domain vcpu pointer array
A domain's primary array of vcpu pointers can be allocated by a toolstack exactly once in the lifetime of a domain via the XEN_DOMCTL_max_vcpus hypercall. This array is leaked on domain teardown. This memory leak could over time exhaust the host's memory.
A domain given partial management control via XEN_DOMCTL_max_vcpus can mount a denial of service attack affecting the whole system. The ability to also restart or create suitable domains is also required to fully exploit the issue. Without this the leak is limited to a small multiple of the maximum number of vcpus for the domain. The maximum leak is 64kbytes per domain (re)boot (less on ARM).
This issue is only relevant to systems which intend to increase security through th
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00063.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/77364http://www.securitytracker.com/id/1034033http://xenbits.xen.org/xsa/advisory-149.htmlhttp://xenbits.xen.org/xsa/advisory-151.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00063.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/77364http://www.securitytracker.com/id/1034033http://xenbits.xen.org/xsa/advisory-149.htmlhttp://xenbits.xen.org/xsa/advisory-151.htmlhttps://security.gentoo.org/glsa/201604-03
2015-10-30
Published