CVE-2015-8550
published 2016-04-14CVE-2015-8550: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by…
PriorityP337high8.2CVSS 3.0
AVLACLPRHUINSCCHIHAH
EPSS
1.08%
61.3th percentile
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.3-3 (bookworm) | linux 4.3.3-3 (bookworm) |
| debian | qemu | < linux 4.3.3-3 (bookworm) | linux 4.3.3-3 (bookworm) |
| debian | xen | < linux 4.3.3-3 (bookworm) | linux 4.3.3-3 (bookworm) |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 4.3.3-3 | 4.3.3-3 |
| linux | linux_kernel | >= 0 < 3.13.0-74.118 | 3.13.0-74.118 |
| novell | suse_linux_enterprise_real_time_extension | — | — |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-2 | 1:2.5+dfsg-2 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.22 | 2.0.0+dfsg-2ubuntu1.22 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.05.7MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:C
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cv84-8x9g-5qcr: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges
ghsa_unreviewed·2022-05-17
CVE-2015-8550 [HIGH] CWE-284 GHSA-cv84-8x9g-5qcr: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
OSV
CVE-2015-8550: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges
osv·2016-04-14·CVSS 8.2
CVE-2015-8550 [HIGH] CVE-2015-8550: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
OSV
qemu, qemu-kvm vulnerabilities
osv·2016-02-03·CVSS 6.0
CVE-2015-7549 [MEDIUM] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-7549)
Lian Yihan discovered that QEMU incorrectly handled the VNC server. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service. (CVE-2015-8504)
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Qinghao Tang discovered th
OSV
linux-lts-wily vulnerabilities
osv·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messag
OSV
linux-lts-vivid vulnerabilities
osv·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messa
OSV
linux-lts-utopic vulnerabilities
osv·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() mess
OSV
linux vulnerabilities
osv·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] linux vulnerabilities
linux vulnerabilities
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messages causin
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2016-02-03·CVSS 6.0
CVE-2015-7549 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An
attacker inside the guest could use this issue to cause QEMU to crash,
resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 15.10. (CVE-2015-7549)
Lian Yihan discovered that QEMU incorrectly handled the VNC server. A
remote attacker could use this issue to cause QEMU to crash, resulting in a
denial of service. (CVE-2015-8504)
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on th
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-12-20·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw t
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a de
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a de
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-12-19·CVSS 8.2
CVE-2015-8550 [HIGH] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)
Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device's state. An attacker could exploit this
flaw
Red Hat
xen: paravirtualized drivers incautious about shared memory contents (XSA-155)
vendor_redhat·2015-12-17·CVSS 8.2
CVE-2015-8550 [HIGH] xen: paravirtualized drivers incautious about shared memory contents (XSA-155)
xen: paravirtualized drivers incautious about shared memory contents (XSA-155)
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-8550: linux - Xen, when used on a system providing PV backends, allows local guest OS administ...
vendor_debian·2015·CVSS 8.2
CVE-2015-8550 [HIGH] CVE-2015-8550: linux - Xen, when used on a system providing PV backends, allows local guest OS administ...
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Scope: local
bookworm: resolved (fixed in 4.3.3-3)
bullseye: resolved (fixed in 4.3.3-3)
forky: resolved (fixed in 4.3.3-3)
sid: resolved (fixed in 4.3.3-3)
trixie: resolved (fixed in 4.3.3-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
bugzilla·2015-12-17·CVSS 4.9
CVE-2015-8554 [MEDIUM] CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2015-8550 xsa155 xen: paravirtualized drivers incautious about shared memory contents (XSA-155)
bugzilla·2015-12-07·CVSS 8.2
CVE-2015-8550 [HIGH] CVE-2015-8550 xsa155 xen: paravirtualized drivers incautious about shared memory contents (XSA-155)
CVE-2015-8550 xsa155 xen: paravirtualized drivers incautious about shared memory contents (XSA-155)
ISSUE DESCRIPTION
The compiler can emit optimizations in the PV backend drivers which
can lead to double fetch vulnerabilities. Specifically the shared
memory between the frontend and backend can be fetched twice (during
which time the frontend can alter the contents) possibly leading to
arbitrary code execution in backend.
IMPACT
Malicious guest administrators can cause denial of service. If driver
domains are not in use, the impact can be a host crash, or privilege escalation.
VULNERABLE SYSTEMS
Systems running PV or HVM guests are vulnerable.
ARM and x86 systems are vulnerable.
All OSes providing PV backends are susceptible, this includes
Linux and NetBSD. By default the Linux dis
arXiv
Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
arxiv_fulltext·2017-11-03
Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
Automated Detection, Exploitation, and Elimination of Double-Fetch Bugs using Modern CPU Features
Michael Schwarz^1, Daniel Gruss^1, Moritz Lipp^1, Clémentine Maurice^2,\ Schuster^1, Anders Fogh^3, Stefan Mangard^1
^1 Graz University of Technology, Austria
^2 CNRS, IRISA, France
^3 G DATA Advanced Analytics, Germany
## Abstract
Double-fetch bugs are a special type of race condition, where an unprivileged execution thread is able to change a memory location between the time-of-check and time-of-use of a privileged execution thread.
If an unprivileged attacker changes the value at the right time, the privileged operation becomes inconsistent, leading to a change in control flow, and thus an escalation of privileges for the attacker.
More severely, such double-fetch bugs can be introduced
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3434http://www.debian.org/security/2016/dsa-3471http://www.debian.org/security/2016/dsa-3519http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/79592http://www.securitytracker.com/id/1034479http://xenbits.xen.org/xsa/advisory-155.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3434http://www.debian.org/security/2016/dsa-3471http://www.debian.org/security/2016/dsa-3519http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/79592http://www.securitytracker.com/id/1034479http://xenbits.xen.org/xsa/advisory-155.htmlhttps://security.gentoo.org/glsa/201604-03
2016-04-14
Published