LWN.net Logo

xen: denial of service

Package(s):xen CVE #(s):CVE-2012-5634 CVE-2013-0154
Created:January 23, 2013 Updated:February 4, 2013
Description: From the Red Hat bugzilla:

When passing a device which is behind a legacy PCI Bridge through to a guest Xen incorrectly configures the VT-d hardware. This could allow incorrect interrupts to be injected to other guests which also have passthrough devices.

In a typical Xen system many devices are owned by domain 0 or driver domains, leaving them vulnerable to such an attack. Such a DoS is likely to have an impact on other guests running in the system.

On systems using Intel VT-d for PCI passthrough a malicious domain, given access to a device which is behind a legacy PCI bridge, can mount a denial of service attack affecting the whole system.

Alerts:
Fedora FEDORA-2013-0627 2013-01-23
Fedora FEDORA-2013-0608 2013-01-23
Fedora FEDORA-2013-1274 2013-02-02
Debian DSA-2636-1 2013-03-01
Debian DSA-2636-2 2013-03-03
openSUSE openSUSE-SU-2013:0636-1 2013-04-08
openSUSE openSUSE-SU-2013:0637-1 2013-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds