CVE-2015-8554: Xen
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
Affected products
- Xen Xen: up to and including 4.6.1
Published 2016-04-14. Last modified 2026-06-17.