CVE-2015-7970
published 2015-10-30CVE-2015-7970: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.44%
35.4th percentile
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
| xen | xen | >= 0 < 4.6.0-1 | 4.6.0-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3g2j-g4j4-88m6: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod
ghsa_unreviewed·2022-05-17
CVE-2015-7970 [MEDIUM] GHSA-3g2j-g4j4-88m6: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
OSV
CVE-2015-7970: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod
osv·2015-10-30·CVSS 4.9
CVE-2015-7970 [MEDIUM] CVE-2015-7970: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
Red Hat
xen: Long latency populate-on-demand operation is not preemptible on x86
vendor_redhat·2015-10-29·CVSS 4.9
CVE-2015-7970 [MEDIUM] xen: Long latency populate-on-demand operation is not preemptible on x86
xen: Long latency populate-on-demand operation is not preemptible on x86
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
Mitigation: Running only PV guests will avoid this issue. Running HVM guest without enabling Populate-on-Demand mode (so, ensuring that maxmem==memory) will avoid this issue.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-7970: xen - The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5....
vendor_debian·2015·CVSS 4.9
CVE-2015-7970 [MEDIUM] CVE-2015-7970: xen - The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5....
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
bugzilla·2015-10-29·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2015-7970 xen: Long latency populate-on-demand operation is not preemptible on x86
bugzilla·2015-10-16·CVSS 4.9
CVE-2015-7970 [MEDIUM] CVE-2015-7970 xen: Long latency populate-on-demand operation is not preemptible on x86
CVE-2015-7970 xen: Long latency populate-on-demand operation is not preemptible on x86
When running an HVM domain in Populate-on-Demand mode, Xen would sometimes search the domain for memory to reclaim, in response to demands for population of other pages in the same domain. This search runs without preemption. The guest can, by suitable arrangement of its memory contents, create a situation where this search is a time-consuming linear scan of the guest's address space. The scan might be triggered by the guest's own actions, or by toolstack operations such as migration.
A malicious administrator of a suitable guest can cause a denial of service. Specifically, such a guest can prevent use of a physical CPU for a significant period. If the host watchdog is in use, this can lead to a watchd
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/77362http://www.securitytracker.com/id/1034034http://xenbits.xen.org/xsa/advisory-150.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/77362http://www.securitytracker.com/id/1034034http://xenbits.xen.org/xsa/advisory-150.htmlhttps://security.gentoo.org/glsa/201604-03
2015-10-30
Published