#VU3002 Improper check or handling of exceptional conditions in Linux kernel and Xen - CVE-2015-8104
Published: November 30, -0001 / Updated: April 17, 2018
Vulnerability identifier: #VU3002
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2015-8104
CWE-ID: CWE-703
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Xen
Linux kernel
Xen
Software vendor:
Linux Foundation
Xen Project
Linux Foundation
Xen Project
Description
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The weakness exists in the KVM subsystem due to many #DB (aka Debug) exceptions, related to svm.c. An adjacent attacker can cause the service to crash.
The weakness exists in the KVM subsystem due to many #DB (aka Debug) exceptions, related to svm.c. An adjacent attacker can cause the service to crash.
Remediation
Update Linux Kernel to 4.2.7 or Xen to 4.7.