CVE-2015-8550 describes a double-fetch vulnerability in Xen, specifically affecting systems with PV backends. This flaw allows a local guest OS administrator to trigger a host OS crash (denial of service) or escalate privileges by manipulating shared memory. The vulnerability carries a CVSS v3 score of 8.2 (HIGH), indicating a high severity due to its local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. However, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_real_time_extension:12:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.