<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 18:41:36 +0000</lastBuildDate>
    <item>
      <title>CVE-2015-8551</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2015-8551</link>
      <description>&lt;p&gt;The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka &amp;#34;Linux pciback missing sanity checks.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka &amp;#34;Linux pciback missing sanity checks.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2015-8551</guid>
    </item>
    <item>
      <title>USN-2848-1 — linux vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-2848-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: linux&lt;/p&gt;
&lt;p&gt;Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)&lt;/p&gt;
&lt;p&gt;Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device&amp;#39;s state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)&lt;/p&gt;
&lt;p&gt;Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device&amp;#39;s state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messages causing the initial domain to exhaust disk space.
(CVE-2015-8552)&lt;/p&gt;
&lt;p&gt;Jann Horn discovered a ptrace issue with user namespaces in the Linux
kernel. The namespace owner could potentially exploit this flaw by ptracing
a root owned process entering the user namespace to elevate its privileges
and potentially gain access outside of the namespace.
(http://bugs.launchpad.net/bugs/1527374, CVE-2015-8709)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: linux&lt;/p&gt;
&lt;p&gt;Felix Wilhelm discovered a race condition in the Xen paravirtualized
drivers which can cause double fetch vulnerabilities. An attacker in the
paravirtualized guest could exploit this flaw to cause a denial of service
(crash the host) or potentially execute arbitrary code on the host.
(CVE-2015-8550)&lt;/p&gt;
&lt;p&gt;Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device&amp;#39;s state. An attacker could exploit this
flaw to cause a denial of service (NULL dereference) on the host.
(CVE-2015-8551)&lt;/p&gt;
&lt;p&gt;Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not
perform consistency checks on the device&amp;#39;s state. An attacker could exploit this
flaw to cause a denial of service by flooding the logging system with
WARN() messages causing the initial domain to exhaust disk space.
(CVE-2015-8552)&lt;/p&gt;
&lt;p&gt;Jann Horn discovered a ptrace issue with user namespaces in the Linux
kernel. The namespace owner could potentially exploit this flaw by ptracing
a root owned process entering the user namespace to elevate its privileges
and potentially gain access outside of the namespace.
(http://bugs.launchpad.net/bugs/1527374, CVE-2015-8709)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-2848-1</guid>
    </item>
  </channel>
</rss>
