CVE-2015-7972
published 2015-10-30CVE-2015-7972: The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.43%
34.5th percentile
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.6.0-1 (bookworm) | xen 4.6.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pv8-hfx7-rfh8: The (1) libxl_set_memory_target function in tools/libxl/libxl
ghsa_unreviewed·2022-05-14
CVE-2015-7972 [LOW] GHSA-4pv8-hfx7-rfh8: The (1) libxl_set_memory_target function in tools/libxl/libxl
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
OSV
CVE-2015-7972: The (1) libxl_set_memory_target function in tools/libxl/libxl
osv·2015-10-30·CVSS 2.1
CVE-2015-7972 [LOW] CVE-2015-7972: The (1) libxl_set_memory_target function in tools/libxl/libxl
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
Red Hat
xen: populate-on-demand balloon size inaccuracy can crash guests on x86
vendor_redhat·2015-10-29·CVSS 2.1
CVE-2015-7972 [LOW] xen: populate-on-demand balloon size inaccuracy can crash guests on x86
xen: populate-on-demand balloon size inaccuracy can crash guests on x86
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
Mitigation: Reducing the guest's memory target, after guest startup, can cause the
guest's ballon driver to eliminate the PoD discrepancy. If the guest
successfully balloons down, it will no longer be vulnerable.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-7972: xen - The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__b...
vendor_debian·2015·CVSS 2.1
CVE-2015-7972 [LOW] CVE-2015-7972: xen - The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__b...
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
Scope: local
bookworm: resolved (fixed in 4.6.0-1)
bullseye: resolved (fixed in 4.6.0-1)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.6.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
bugzilla·2015-10-29·CVSS 4.9
CVE-2015-7969 [MEDIUM] CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
CVE-2015-7969 CVE-2015-7970 CVE-2015-7813 CVE-2015-7814 CVE-2015-7812 CVE-2015-7971 CVE-2015-7835 CVE-2015-7972 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2015-7972 xen: populate-on-demand balloon size inaccuracy can crash guests on x86
bugzilla·2015-10-28·CVSS 2.1
CVE-2015-7972 [LOW] CVE-2015-7972 xen: populate-on-demand balloon size inaccuracy can crash guests on x86
CVE-2015-7972 xen: populate-on-demand balloon size inaccuracy can crash guests on x86
The design of the memory populate-on-demand (PoD) system requires that
a guest's memory ballooning driver reach its memory reduction target.
The target is not entirely well-defined in terms of the information
visible to the appropriate parts of the system, so some unknown set of
guests (but probably most guests) will fail this criterion.
If the guest memory balloon driver does not free sufficient memory to
reach its target, the guest will proceed to run with a nonzero number
of outstanding PoD pages. When the guest or management toolstack
touches such a page, the hypervisor would search the guest memory for
a page containing only zeroes.
If no such page is found, the guest crashes. Prior to the patch f
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00063.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/77365http://www.securitytracker.com/id/1034036http://xenbits.xen.org/xsa/advisory-153.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00063.htmlhttp://support.citrix.com/article/CTX202404http://www.debian.org/security/2015/dsa-3414http://www.securityfocus.com/bid/77365http://www.securitytracker.com/id/1034036http://xenbits.xen.org/xsa/advisory-153.htmlhttps://security.gentoo.org/glsa/201604-03
2015-10-30
Published