CVE-2015-7970XEN vulnerability

CWE-3997 documents6 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 78.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 30
Latest updateMay 17

Description

The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages3 packages

debiandebian/xen< xen 4.6.0-1 (bookworm)
Debianxen/xen< 4.6.0-1+3
NVDxen/xen5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-3g2j-g4j4-88m6: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod2022-05-17
OSV
CVE-2015-7970: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod2015-10-30

📋Vendor Advisories

2
Red Hat
xen: Long latency populate-on-demand operation is not preemptible on x862015-10-29
Debian
CVE-2015-7970: xen - The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5....2015

💬Community

2
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]2015-10-29
Bugzilla
CVE-2015-7970 xen: Long latency populate-on-demand operation is not preemptible on x862015-10-16