CVE-2015-7311: Xen
Low severity, CVSS 3.6. EPSS: 0.4% chance of exploitation in the next 30 days.
libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image.
Affected products
- Xen Xen: version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.1.3 only; version 4.1.4 only; version 4.1.5 only; …
Published 2015-10-01. Last modified 2026-06-17.