CVE-2015-3340

low
Published 2015-04-28 · Modified 2026-05-06
CVSS v3
CVSS v2
2.9
VIR risk
2.9

Description

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-3340

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://xenbits.xen.org/xsa/advisory-132.html

OS impact

OSVersionStatusFixed in
debian debian7.0affected
debian debian8.0affected
suse suse11.0affected
suse suse13.1affected
suse suse12affected
fedora fedora20affected
fedora fedora21affected
fedora fedora22affected
debian debianbookwormfixed4.6.0-1
debian debianbullseyefixed4.6.0-1
debian debianforkyfixed4.6.0-1
debian debiansidfixed4.6.0-1
debian debiantrixiefixed4.6.0-1

Application impact

VendorProductVersionsFixed
suse susesuse_linux_enterprise_software_development_kit11.0

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.