PT-2013-4430 · Xen+2 · Xen+2

Gábor Pék

·

Published

2013-08-28

·

Updated

2024-06-15

·

CVE-2013-3495

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.3.x through 4.3.x
Description The issue allows local guests to cause a denial of service, resulting in a kernel panic. This is achieved by sending a malformed Message Signaled Interrupt (MSI) from a PCI device capable of bus mastering, which triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
Recommendations For Xen versions 3.3.x through 4.3.x, consider disabling the Interrupt Remapping engine as a temporary workaround until a patch is available. Restrict access to PCI devices that are bus mastering capable to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1616
ALT-PU-2014-1683
CVE-2013-3495
OPENSUSE-SU-2015_0226-1
OPENSUSE-SU-2015_0256-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2014_1710-1
SUSE-SU-2014_1732-1
SUSE-SU-2015:0940-1
SUSE-SU-2015_0022-1
SUSE-SU-2015_0744-1

Affected Products

Alt Linux
Suse
Xen