CVE-2015-7969 describes multiple memory leak vulnerabilities in Xen versions 4.0 through 4.6.x. These flaws allow local guest administrators or domains with specific permissions to trigger a denial of service by exhausting memory through repeated "teardowns" of domains, specifically when vcpu pointer arrays are allocated via XEN_DOMCTL_max_vcpus or xenoprofile state vcpu pointer arrays are allocated via XENOPROF_get_buffer or XENOPROF_set_passive hypercalls. The vulnerability has a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), indicating a low attack complexity where a local attacker can achieve a complete denial of service. While the EPSS score is very low, suggesting minimal exploitability in the wild, the potential impact on system availability is high. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article found, suggesting limited attention to this particular CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.0.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:xen:xen:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.