Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ben Serebrin

Pesquisador deGoogle Inc.
#49789de 53,638
4.9CVSS total
Vulnerabilidades · 1
PT-2015-2741
4.9
2015-08-31
Xen · Xen · CVE-2015-5307
**Name of the Vulnerable Software and Affected Versions** Linux kernel versions prior to 4.2.7 Xen versions 4.3.x through 4.6.x **Description** The issue is related to errors in resource management within the KVM subsystem of the Linux kernel and the Xen hypervisor. It allows a local attacker to cause a denial of service by triggering many Alignment Check exceptions, which can lead to a host OS panic or hang. This is related to the svm.c and vmx.c files. **Recommendations** For Linux kernel versions prior to 4.2.7, update to version 4.2.7 or later to resolve the issue. For Xen versions 4.3.x through 4.6.x, consider disabling the KVM subsystem temporarily until a patch is available. Restrict access to the svm.c and vmx.c components to minimize the risk of exploitation.