PT-2013-1818 · Xen+1 · Xen+1
Published
2013-02-14
·
Updated
2024-06-15
·
CVE-2012-5634
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.0, 4.1.x, 4.2.x
Description
The issue arises when Xen uses Intel VT-d for PCI passthrough and does not properly configure VT-d for devices behind a legacy PCI Bridge. This allows local guests to cause a denial of service to other guests by injecting an interrupt.
Recommendations
For versions 4.0, 4.1.x, and 4.2.x, consider disabling the PCI passthrough feature for devices behind a legacy PCI Bridge until a proper configuration method is available. Restrict access to the VT-d configuration to minimize the risk of exploitation. Avoid using the Intel VT-d for PCI passthrough with devices behind a legacy PCI Bridge in these versions.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen