← Back

CVE-2015-8555

nvd nist
Published: Apr 13, 2016Modified: May 6, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.

Affected (17)

Products: Citrix: Xenserver · Xen: Xen
1 product
Xenserver
1 product
Xen
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration B
16 vulnerable
Vulnerable SoftwareAffected Versions
Xen
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.4
Version 4.4.0
Version 4.4.1
Version 4.4.2
Version 4.4.3
Version 4.4.4
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.6.0
Version 4.6.1

References (14)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.