PT-2020-14584 · Project Acrn · Acrn Project
Published
2020-08-31
·
Updated
2020-09-08
·
CVE-2020-15687
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ACRN Project versions 1.6.1 through 2.0
Description
The issue is related to missing access control restrictions in the Hypervisor component, allowing a malicious entity with root access in the Service VM userspace to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This results in a corrupt state and Denial of Service (DoS) for previously assigned PCIe devices to the Service VM at runtime.
Recommendations
For ACRN Project versions 1.6.1 through 2.0, consider restricting access to the Hypervisor component and the PCIe assign/de-assign Hypercalls to prevent abuse. As a temporary workaround, restrict the use of crafted ioctls and payloads in the Service VM userspace to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acrn Project