PT-2015-1367 · Xen+2 · Xen+2

Jan Beulich

·

Published

2015-06-03

·

Updated

2024-06-15

·

CVE-2015-4104

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.3.x through 4.5.x
Description The issue is related to insufficient access restrictions to certain functions in the Xen hypervisor. This can be exploited by an attacker, potentially allowing them to cause a denial of service using a guest operating system. The exploitation can lead to unexpected interrupts and host crashes.
Recommendations For Xen versions 3.3.x through 4.5.x, consider restricting access to the PCI MSI mask bits to prevent local x86 HVM guest users from causing a denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-10459
CVE-2015-4104
DSA-3284-1
DSA-3286-1
MGASA-2015-0310
MGASA-2016-0098
OPENSUSE-SU-2015_1092-1
OPENSUSE-SU-2015_1094-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2015:1042-1
SUSE-SU-2015:1045-1
SUSE-SU-2015:1156-1
SUSE-SU-2015:1157-1
USN-2630-1

Affected Products

Suse
Ubuntu
Xen