CVE-2015-2044
Summary
| CVE | CVE-2015-2044 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-12 14:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Xen | Xen | 3.2.0 | All | All | All |
| Operating System | Xen | Xen | 3.2.1 | All | All | All |
| Operating System | Xen | Xen | 3.2.2 | All | All | All |
| Operating System | Xen | Xen | 3.2.3 | All | All | All |
| Operating System | Xen | Xen | 3.3.0 | All | All | All |
| Operating System | Xen | Xen | 3.3.1 | All | All | All |
| Operating System | Xen | Xen | 3.3.2 | All | All | All |
| Operating System | Xen | Xen | 3.4.0 | All | All | All |
| Operating System | Xen | Xen | 3.4.1 | All | All | All |
| Operating System | Xen | Xen | 3.4.2 | All | All | All |
| Operating System | Xen | Xen | 3.4.3 | All | All | All |
| Operating System | Xen | Xen | 3.4.4 | All | All | All |
| Operating System | Xen | Xen | 4.0.0 | All | All | All |
| Operating System | Xen | Xen | 4.0.1 | All | All | All |
| Operating System | Xen | Xen | 4.0.2 | All | All | All |
| Operating System | Xen | Xen | 4.0.3 | All | All | All |
| Operating System | Xen | Xen | 4.0.4 | All | All | All |
| Operating System | Xen | Xen | 4.1.0 | All | All | All |
| Operating System | Xen | Xen | 4.1.1 | All | All | All |
| Operating System | Xen | Xen | 4.1.2 | All | All | All |
| Operating System | Xen | Xen | 4.1.3 | All | All | All |
| Operating System | Xen | Xen | 4.1.4 | All | All | All |
| Operating System | Xen | Xen | 4.1.5 | All | All | All |
| Operating System | Xen | Xen | 4.1.6.1 | All | All | All |
| Operating System | Xen | Xen | 4.2.0 | All | All | All |
| Operating System | Xen | Xen | 4.2.1 | All | All | All |
| Operating System | Xen | Xen | 4.2.2 | All | All | All |
| Operating System | Xen | Xen | 4.2.3 | All | All | All |
| Operating System | Xen | Xen | 4.3.0 | All | All | All |
| Operating System | Xen | Xen | 4.3.1 | All | All | All |
| Operating System | Xen | Xen | 4.4.0 | All | All | All |
| Operating System | Xen | Xen | 4.4.0 | rc1 | All | All |
| Operating System | Xen | Xen | 4.4.1 | - | All | All |
| Operating System | Xen | Xen | 4.5.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security_Advisory-Xen Vulnerabilities on Huawei FusionSphere products - Huawei PSIRT | af854a3a-2127-422b-91ae-364da2661108 | www1.huawei.com | |
| Xen: Multiple vulnerabilities (GLSA 201504-04) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Xen Multiple Flaws Let Local Guest Users Deny Service or Obtain Information From Other Guest Systems - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [SECURITY] Fedora 21 Update: xen-4.4.1-16.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 20 Update: xen-4.3.3-12.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 22 Update: xen-4.5.0-6.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Xen x86 Device Emulation Bug Lets Local Guest Users Obtain Information From Other Guest Systems - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Citrix XenServer Multiple Security Updates | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | |
| [security-announce] openSUSE-SU-2015:0732-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Xen CVE-2015-2044 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| XSA-121 - Xen Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | xenbits.xen.org | |
| Debian -- Security Information -- DSA-3181-1 xen | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.