CVE-2015-2752: Fedoraproject Fedora
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
Affected products
- Fedoraproject Fedora: version 20 only; version 21 only
- Xen Xen: version 4.3.0 only; version 4.3.1 only; version 4.3.2 only; version 4.4.0 only; version 4.4.1 only; version 4.5.0 only
Published 2015-04-01. Last modified 2026-06-17.