CVE-2015-8341
published 2015-12-17CVE-2015-8341: The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.04%
79.0th percentile
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcgw-prmf-2x36: The libxl toolstack library in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2015-8341 [HIGH] GHSA-qcgw-prmf-2x36: The libxl toolstack library in Xen 4
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
OSV
CVE-2015-8341: The libxl toolstack library in Xen 4
osv·2015-12-17·CVSS 7.8
CVE-2015-8341 [HIGH] CVE-2015-8341: The libxl toolstack library in Xen 4
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
Red Hat
xen: libxl leak of PV kernel can cause OOM condition
vendor_redhat·2015-12-08·CVSS 7.8
CVE-2015-8341 [HIGH] CWE-400 xen: libxl leak of PV kernel can cause OOM condition
xen: libxl leak of PV kernel can cause OOM condition
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-8341: xen - The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release...
vendor_debian·2015·CVSS 7.8
CVE-2015-8341 [HIGH] CVE-2015-8341: xen - The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release...
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8629 krb5: xdr_nullstring() doesn't check for terminating null character
bugzilla·2016-01-28·CVSS 5.3
CVE-2015-8629 [MEDIUM] CVE-2015-8629 krb5: xdr_nullstring() doesn't check for terminating null character
CVE-2015-8629 krb5: xdr_nullstring() doesn't check for terminating null character
It was reported that in all versions of MIT krb5, an authenticated attacker can cause kadmind to read beyond the end of allocated memory by sending a string without a terminating zero byte. Information leakage may be possible for an attacker with permission to modify the database.
Upstream patch:
https://github.com/krb5/krb5/commit/df17a1224a3406f57477bcd372c61e04c0e5a5bb
Discussion:
Created krb5 tracking bugs for this issue:
Affects: fedora-all [bug 1302618]
---
Upstream bug report:
http://krbdev.mit.edu/rt/Ticket/Display.html?id=8341
Fixed upstream in krb5 1.14.1:
http://web.mit.edu/kerberos/krb5-1.14/krb5-1.14.1.html
The upstream bug report also indicates the issue will be fixed in 1.13.4.
---
Bugzilla
CVE-2015-8338 CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 xen: various flaws [fedora-all]
bugzilla·2015-12-08·CVSS 7.2
CVE-2015-8338 [HIGH] CVE-2015-8338 CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 xen: various flaws [fedora-all]
CVE-2015-8338 CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2015-8341 xen: libxl leak of PV kernel can cause OOM condition
bugzilla·2015-11-24·CVSS 7.8
CVE-2015-8341 [HIGH] CVE-2015-8341 xen: libxl leak of PV kernel can cause OOM condition
CVE-2015-8341 xen: libxl leak of PV kernel can cause OOM condition
When constructing a guest which is configured to use a PV bootloader which runs as a userspace process in the toolstack domain (e.g. pygrub) libxl creates a mapping of the files to be used as kernel and initial ramdisk when building the guest domain.
However if building the domain subsequently fails these mappings would not be released leading to a leak of virtual address space in the calling process, as well as preventing the recovery of the temporary disk files containing the kernel and initial ramdisk.
For toolstacks which manage multiple domains within the same process, an attacker who is able to repeatedly start a suitable domain (or many such domains) can cause an out-of-memory condition in the toolstack process, l
http://www.debian.org/security/2016/dsa-3519http://www.securitytracker.com/id/1034389http://xenbits.xen.org/xsa/advisory-160.htmlhttps://security.gentoo.org/glsa/201604-03http://www.debian.org/security/2016/dsa-3519http://www.securitytracker.com/id/1034389http://xenbits.xen.org/xsa/advisory-160.htmlhttps://security.gentoo.org/glsa/201604-03
2015-12-17
Published