xen: leak of main per-domain vcpu pointer array
Published Oct 30, 2015
4.9
MEDIUMCVSS 2.0
EPSS 0.44%
Description
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.
Affected products
No data.
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.5
- 4.1.6.1
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.4
- 4.4.0
- 4.4.1
- 4.5.0
- 4.5.1
- 4.6.0
No data.
Red Hat Enterprise Linux 5
xen
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
The leak is small. Preventing the creation of large numbers of new domains, and limiting the number of times an existing domain can be rebooted, can reduce the impact of this vulnerability. Switching from disaggregated to a non-disaggregated operation does NOT mitigate the XEN_DOMCTL_max_vcpus vulnerability. Rather, it simply recategorises the vulnerability to hostile management code, regarding it "as designed"; thus it merely reclassifies these issues as "not a bug". Users and vendors of disaggregated systems should not change their configuration.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.44% (0.00436) | 35.63th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.44% (0.00436) | 34.59th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.10% (0.00102) | 25.66th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00062) | 28.60th | v3 (v2023.03.01) |
| Jun 13, 2024 | 0.06% (0.00062) | 26.61th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00062) | 24.59th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (15)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171082.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171185.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171249.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00063.html vendor-advisoryx_refsource_SUSE
- http://support.citrix.com/article/CTX202404 x_refsource_CONFIRM
- http://www.debian.org/security/2015/dsa-3414 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/77364 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1034033 vdb-entryx_refsource_SECTRACK
- http://xenbits.xen.org/xsa/advisory-149.html x_refsource_CONFIRMVendor Advisory
- http://xenbits.xen.org/xsa/advisory-151.html x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/security/cve/CVE-2015-7969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1272519 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-7969
- https://security.gentoo.org/glsa/201604-03 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-7969
Change history (0)
No recorded changes yet.