CVE-2015-7970: Xen

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.

Affected products

  • Xen Xen: version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; version 3.4.3 only; version 3.4.4 only

Published 2015-10-30. Last modified 2026-06-17.