CVE-2015-8339
published 2015-12-17CVE-2015-8339: The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS…
PriorityP416medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.38%
30.5th percentile
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8m33-9wjx-3vfj: The memory_exchange function in common/memory
ghsa_unreviewed·2022-05-17
CVE-2015-8339 [MEDIUM] GHSA-8m33-9wjx-3vfj: The memory_exchange function in common/memory
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
OSV
CVE-2015-8339: The memory_exchange function in common/memory
osv·2015-12-17·CVSS 4.7
CVE-2015-8339 [MEDIUM] CVE-2015-8339: The memory_exchange function in common/memory
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
Red Hat
xen: XENMEM_exchange error handling may cause DoS to host
vendor_redhat·2015-12-08·CVSS 4.7
CVE-2015-8339 [MEDIUM] CWE-667 xen: XENMEM_exchange error handling may cause DoS to host
xen: XENMEM_exchange error handling may cause DoS to host
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
A malicious guest administrator may be able to deny service by crashing the host or causing a deadlock by timing memory handling events between the guest and the host.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat
Enterprise Linux 6, 7, MRG-2 and realtime kernels.
At this time, there is no plans to fix this issue, if you feel that this issue
is affecting your deployment and have an EUS subscription, please contact
support to have this
Debian
CVE-2015-8339: xen - The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does ...
vendor_debian·2015·CVSS 4.7
CVE-2015-8339 [MEDIUM] CVE-2015-8339: xen - The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does ...
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8338 CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 xen: various flaws [fedora-all]
bugzilla·2015-12-08·CVSS 7.2
CVE-2015-8338 [HIGH] CVE-2015-8338 CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 xen: various flaws [fedora-all]
CVE-2015-8338 CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2015-8339 CVE-2015-8340 xen: XENMEM_exchange error handling may cause DoS to host
bugzilla·2015-11-24·CVSS 4.7
CVE-2015-8339 [MEDIUM] CVE-2015-8339 CVE-2015-8340 xen: XENMEM_exchange error handling may cause DoS to host
CVE-2015-8339 CVE-2015-8340 xen: XENMEM_exchange error handling may cause DoS to host
CVE-2015-8339:
Error handling in the operation may involve handing back pages to the domain. This operation may fail when in parallel the domain gets torn down. So far this failure unconditionally resulted in the host being brought down due to an internal error being assumed.
CVE-2015-8340:
Furthermore error handling so far wrongly included the release of a lock. That lock, however, was either not acquired or already released on all paths leading to the error handling sequence.
A malicious guest administrator may be able to deny service by crashing the host or causing a deadlock.
All Xen versions from at least 3.2 onwards are vulnerable. Older versions have not been inspected.
The vulnerability can b
http://support.citrix.com/article/CTX203451http://www.debian.org/security/2016/dsa-3519http://www.securityfocus.com/bid/79038http://www.securitytracker.com/id/1034391http://xenbits.xen.org/xsa/advisory-159.htmlhttps://security.gentoo.org/glsa/201604-03http://support.citrix.com/article/CTX203451http://www.debian.org/security/2016/dsa-3519http://www.securityfocus.com/bid/79038http://www.securitytracker.com/id/1034391http://xenbits.xen.org/xsa/advisory-159.htmlhttps://security.gentoo.org/glsa/201604-03
2015-12-17
Published