PT-2020-14584 · Project Acrn · Acrn Project

Published

2020-08-31

·

Updated

2020-09-08

·

CVE-2020-15687

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ACRN Project versions 1.6.1 through 2.0
Description The issue is related to missing access control restrictions in the Hypervisor component, allowing a malicious entity with root access in the Service VM userspace to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This results in a corrupt state and Denial of Service (DoS) for previously assigned PCIe devices to the Service VM at runtime.
Recommendations For ACRN Project versions 1.6.1 through 2.0, consider restricting access to the Hypervisor component and the PCIe assign/de-assign Hypercalls to prevent abuse. As a temporary workaround, restrict the use of crafted ioctls and payloads in the Service VM userspace to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-15687

Affected Products

Acrn Project