|
|
| |
|
| |
xen: denial of service
| Package(s): | xen |
CVE #(s): | CVE-2012-5634
CVE-2013-0154
|
| Created: | January 23, 2013 |
Updated: | February 4, 2013 |
| Description: |
From the Red Hat bugzilla:
When passing a device which is behind a legacy PCI Bridge through to
a guest Xen incorrectly configures the VT-d hardware. This could allow
incorrect interrupts to be injected to other guests which also have
passthrough devices.
In a typical Xen system many devices are owned by domain 0 or driver
domains, leaving them vulnerable to such an attack. Such a DoS is
likely to have an impact on other guests running in the system.
On systems using Intel VT-d for PCI passthrough a malicious domain,
given access to a device which is behind a legacy PCI bridge, can
mount a denial of service attack affecting the whole system. |
| Alerts: |
|
( Log in to post comments)
|
|
|