PT-2015-5630 · Linux+4 · Linux Kernel+4

Jan Beulich

·

Published

2015-03-12

·

Updated

2019-08-13

·

CVE-2015-2150

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 3.3.x through 4.5.x Linux kernel versions prior to 3.19.1
Description The issue is related to improper restriction of access to PCI command registers. This might allow local guest OS users to cause a denial of service, resulting in a non-maskable interrupt and host crash. The denial of service can be triggered by disabling the memory or I/O decoding for a PCI Express device and then accessing the device, which leads to an Unsupported Request (UR) response.
Recommendations For Xen versions 3.3.x through 4.5.x, update to a version that properly restricts access to PCI command registers. For Linux kernel versions prior to 3.19.1, update to version 3.19.1 or later to resolve the issue.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1291
ALT-PU-2015-1849
CVE-2015-2150
DSA-3237-1
DSA-4497-1
MGASA-2015-0171
MGASA-2015-0172
MGASA-2015-0219
MGASA-2016-0098
OPENSUSE-SU-2015_0713-1
OPENSUSE-SU-2016_0301-1
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0658-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
SUSE-SU-2015:1478-1
SUSE-SU-2015:1592-1
SUSE-SU-2015:1611-1
SUSE-SU-2015:1678-1
USN-2589-1
USN-2590-1
USN-2613-1
USN-2614-1
USN-2631-1
USN-2632-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu
Xen