[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-2150Date: (C)2015-03-13   (M)2024-04-17


Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.9
Exploit Score: 3.9
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: COMPLETE
  
Reference:
SECTRACK-1031806
SECTRACK-1031902
https://seclists.org/bugtraq/2019/Aug/18
BID-73014
DSA-3237
FEDORA-2015-4066
FEDORA-2015-6100
FEDORA-2015-6294
FEDORA-2015-6320
SUSE-SU-2015:0658
SUSE-SU-2015:1478
SUSE-SU-2015:1592
SUSE-SU-2015:1611
USN-2631-1
USN-2632-1
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=af6fc858a35b90e89ea7a7ee58e66628c55c776b
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htm
http://xenbits.xen.org/xsa/advisory-120.html
https://bugzilla.redhat.com/show_bug.cgi?id=1196266
https://github.com/torvalds/linux/commit/af6fc858a35b90e89ea7a7ee58e66628c55c776b

CPE    29
cpe:/o:xen:xen:4.1.6.1
cpe:/o:xen:xen:4.1.0
cpe:/o:xen:xen:4.5.0
cpe:/o:xen:xen:4.1.4
...
CWE    1
CWE-264
OVAL    30
oval:org.secpod.oval:def:702602
oval:org.secpod.oval:def:702593
oval:org.secpod.oval:def:1501010
oval:org.secpod.oval:def:1501013
...

© SecPod Technologies