CVE-2015-8554: Xen

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."

Affected products

  • Xen Xen: up to and including 4.6.1

Published 2016-04-14. Last modified 2026-06-17.