PT-2015-1367 · Xen+2 · Xen+2
Jan Beulich
·
Published
2015-06-03
·
Updated
2024-06-15
·
CVE-2015-4104
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.3.x through 4.5.x
Description
The issue is related to insufficient access restrictions to certain functions in the Xen hypervisor. This can be exploited by an attacker, potentially allowing them to cause a denial of service using a guest operating system. The exploitation can lead to unexpected interrupts and host crashes.
Recommendations
For Xen versions 3.3.x through 4.5.x, consider restricting access to the PCI MSI mask bits to prevent local x86 HVM guest users from causing a denial of service.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Ubuntu
Xen