PT-2015-1386 · Xen+2 · Xen+2
Jan Beulich
·
Publicado
2015-06-03
·
Atualizado
2024-06-15
·
CVE-2015-4105
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.3.x through 4.5.x
Description
The issue is related to resource management errors in the Xen hypervisor. It can be exploited by a local attacker to cause a denial of service by performing certain invalid operations, which can lead to host disk consumption due to logging of error messages.
Recommendations
For Xen versions 3.3.x through 4.5.x, consider disabling the logging of PCI MSI-X pass-through error messages as a temporary workaround to minimize the risk of exploitation. Restrict access to the logging subsystem to prevent local x86 HVM guests from causing a denial of service.
Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Ubuntu
Xen