CVE-2015-8550

Severity
8.2HIGH
EPSS
16.0%
top 5.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 17

Description

Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages8 packages

Debianxen< 4.8.0~rc3-1+3
Debianqemu< 1:2.5+dfsg-2+3
Debianlinux< 4.3.3-3+3
Ubuntulinux< 3.13.0-74.118
Ubuntulinux-lts-wily< 4.2.0-22.27~14.04.1

🔴Vulnerability Details

8
GHSA
GHSA-cv84-8x9g-5qcr: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges2022-05-17
CVEList
CVE-2015-8550: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges2016-04-14
OSV
CVE-2015-8550: Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges2016-04-14
OSV
qemu, qemu-kvm vulnerabilities2016-02-03
OSV
linux-lts-wily vulnerabilities2015-12-20

📋Vendor Advisories

10
Ubuntu
QEMU vulnerabilities2016-02-03
Ubuntu
Linux kernel (OMAP4) vulnerabilities2016-02-01
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2015-12-20
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2015-12-20
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2015-12-19

💬Community

2
Bugzilla
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]2015-12-17
Bugzilla
CVE-2015-8550 xsa155 xen: paravirtualized drivers incautious about shared memory contents (XSA-155)2015-12-07
CVE-2015-8550 (HIGH CVSS 8.2) | cvebase.io