CVE-2015-8552 describes a denial-of-service vulnerability in the PCI backend driver of Xen, affecting systems running Linux kernels 3.1.x through 4.3.x as the driver domain. Specifically, it impacts canonical, debian, novell, and xen products. A local guest administrator can trigger a continuous stream of WARN messages, leading to disk consumption and a denial of service, by manipulating MSI/MSI-X capable PCI devices. The vulnerability has a CVSS v3.0 score of 4.4 (Medium), indicating a local attack vector with low complexity, high privileges required, and a high impact on availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.3CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.1.3:*:*:*:*:*:*:* | ||
3.1.4CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.1.4:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.2.0:*:*:*:*:*:*:* | ||
3.2.1CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.2.1:*:*:*:*:*:*:* | ||
3.2.2CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.