UBUNTU-CVE-2015-7971
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-7971
Summary:
Details: Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in the do_xenoprof_op function in common/xenoprof.c, or (2) HYPERVISOR_xenpmu_op hypercalls, which are not properly handled in the do_xenpmu_op function in arch/x86/cpu/vpmu.c.
References: https://ubuntu.com/security/CVE-2015-7971, http://xenbits.xen.org/xsa/advisory-152.html, https://www.cve.org/CVERecord?id=CVE-2015-7971
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
