PT-2011-3459 · Intel+2 · Intel Vt-D+2

Joanna Rutkowska

·

Published

2011-08-12

·

Updated

2024-06-15

·

CVE-2011-1898

CVSS v2.0

7.4

High

VectorAV:A/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 4.0 through 4.0.1 Xen versions 4.1 through 4.1.0
Description The issue allows guest OS users to gain host OS privileges by using DMA to generate MSI interrupts by writing to the interrupt injection registers, specifically when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping.
Recommendations For Xen versions 4.0 through 4.0.1, update to version 4.0.2 or later. For Xen versions 4.1 through 4.1.0, update to version 4.1.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1898
DSA-2337-1
OPENSUSE-SU-2024:10196-1
RHSA-2011:1189
RHSA-2011:1479
RHSA-2011_1189
RHSA-2011_1479
RHSA-2012:0358

Affected Products

Intel Vt-D
Red Hat
Xen