CVE-2015-7835
EPSS 0.10%xen - security update
Published: 10/30/2015Modified: 4/28/2026
Description
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Affected packages (2)
- Debian/xenfrom 0, < 4.6.0-1
- Debian/xenfrom 0, < 4.1.4-3+deb7u9