The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Oct 30, 2015 |
| Debian | — | Upgrade xen | Dec 14, 2015 | Oct 30, 2015 |
| Freebsd | — | Upgrade xen-tools | Dec 10, 2025 | Nov 11, 2015 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen-tools.Upgrade app-emulation/pvgrub. | Oct 30, 2017 | Oct 30, 2015 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-doc-htmlUpgrade xen-libsUpgrade xen-libs-32bitUpgrade xen-kmp-defaultUpgrade xen-doc-pdfUpgrade xen-kmp-traceUpgrade xen-tools-xendomains-wait-diskUpgrade xen-develUpgrade xen-toolsUpgrade xenUpgrade xen-tools-domU | Dec 18, 2015 | Oct 30, 2015 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Oct 30, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub