Vulnerabilities > CVE-2015-8615 - 7PK - Security Features vulnerability in XEN 4.6.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
network
low complexity
xen
CWE-254
nessus

Summary

The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to cause a denial of service via a large number of changes to the callback method (HVM_PARAM_CALLBACK_IRQ).

Vulnerable Configurations

Part Description Count
OS
Xen
1

Common Weakness Enumeration (CWE)

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DLA-479.NASL
descriptionThis security update fixes a number of security issues in Xen in wheezy. For Debian 7
last seen2020-03-17
modified2016-05-18
plugin id91198
published2016-05-18
reporterThis script is Copyright (C) 2016-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/91198
titleDebian DLA-479-1 : xen security update