CVE-2015-7835: Xen
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Affected products
- Xen Xen: version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; version 3.4.3 only; version 3.4.4 only; version 4.0.0 only; …
Published 2015-10-30. Last modified 2026-06-17.