CVE-2015-2151: Debian Linux

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Fedoraproject Fedora: version 20 only; version 21 only; version 22 only
  • Xen Xen: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.3.0 only; version 3.3.1 only; …

Published 2015-03-12. Last modified 2026-06-17.