CVE-2015-8552: Canonical Ubuntu Linux

Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."

Affected products

  • Canonical Ubuntu Linux: version 12.04 only
  • Debian Debian Linux: version 6.0 only
  • Novell Suse Linux Enterprise Debuginfo: version 11 only
  • Novell Suse Linux Enterprise Real Time Extension: version 11 only; version 12 only
  • Xen Xen: version 3.1.3 only; version 3.1.4 only; version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; …

Published 2016-04-13. Last modified 2026-06-17.