CVE-2015-4103: Xen
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
Affected products
- Xen Xen: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; …
Published 2015-06-03. Last modified 2026-06-17.