PT-2011-4938 · Linux+2 · Linux Kernel+2

Sasha Levin

·

Publicado

2011-11-25

·

Atualizado

2013-06-10

·

CVE-2011-4347

CVSS v2.0

4.0

Média

VetorAV:L/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.1.10
Description The issue is related to the kvm vm ioctl assign device function in the KVM subsystem, which does not verify permission to access PCI configuration space and BAR resources. This allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM ASSIGN PCI DEVICE operation. It is noted that privileged access is still needed to re-program the device, typically achieved by accessing files on the sysfs filesystem, which are usually not accessible to unprivileged users. As a result, a local user could use this flaw to crash the system.
Recommendations To resolve the issue, update the Linux kernel to version 3.1.10 or later. As a temporary workaround, consider restricting access to the kvm vm ioctl assign device function to prevent unauthorized assignment of PCI devices. Additionally, limit access to the sysfs filesystem to prevent re-programming of devices.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_0350
CVE-2011-4347
DSA-2443-1
RHSA-2012:0149
RHSA-2012:0350
RHSA-2012:1042
RHSA-2012_0149
RHSA-2012_0350
USN-1389-1
USN-1405-1
USN-1406-1
USN-1407-1
USN-1409-1
USN-1421-1
USN-1422-1
USN-1425-1
USN-1426-1
USN-1431-1
USN-1433-1
USN-1440-1

Produtos afetados

Centos
Linux Kernel
Red Hat