Improper check or handling of exceptional conditions in Linux kernel and Xen - CVE-2015-5307
Published: November 30, -0001 / Updated: April 17, 2018
Vulnerability identifier: #VU3355
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2015-5307
CWE-ID: CWE-703
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Xen Project
Xen Project
Affected software:
Linux kernel
Xen
Linux kernel
Xen
Detailed vulnerability description
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The weakness exists in the KVM subsystem due to many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c. An adjacent attacker can cause the service to crash.
The weakness exists in the KVM subsystem due to many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c. An adjacent attacker can cause the service to crash.
How to mitigate CVE-2015-5307
Update Linux Kernel to 4.2.7 or Xen to 4.7.