The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xenUpgrade linux-vanilla.Upgrade linux-grsecUpgrade qemu | Aug 30, 2017 | Dec 17, 2015 |
| Debian | — | Upgrade xen | Mar 22, 2016 | Dec 17, 2015 |
| Freebsd | — | Upgrade xen-tools | Dec 10, 2025 | Jan 6, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen-tools.Upgrade app-emulation/pvgrub.Upgrade app-emulation/xen. | Oct 30, 2017 | Dec 17, 2015 |
| Suse | — | Upgrade xen-doc-pdfUpgrade xen-tools-domUUpgrade xen-kmp-paeUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-doc-htmlUpgrade xenUpgrade xen-tools-xendomains-wait-diskUpgrade xen-toolsUpgrade xen-devel | Jan 4, 2016 | Dec 17, 2015 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Dec 17, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub