PT-2013-2136 · Amd+2 · Xen+2

Published

2013-02-14

·

Updated

2024-06-15

·

CVE-2013-0153

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.3, 4.1.x, 4.2.x
Description The issue arises from the AMD IOMMU support in Xen when using AMD-Vi for PCI passthrough. It uses the same interrupt remapping table for the host and all guests. This allows guests to cause a denial of service by injecting an interrupt into other guests.
Recommendations For Xen versions 3.3, 4.1.x, 4.2.x, consider disabling the AMD IOMMU support or restricting PCI passthrough to minimize the risk of exploitation until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-0153
DSA-2636-1
OPENSUSE-SU-2024:10196-1
RHSA-2013:0847
RHSA-2013_0847
SUSE-SU-2015:0944-1

Affected Products

Red Hat
Suse
Xen