CVE-2015-2044: Xen

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.

Affected products

  • Xen Xen: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.3.0 only; version 3.3.1 only; …

Published 2015-03-12. Last modified 2026-06-17.