Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.
CVSS Details
- CVSS 3.1 Base Score: 5.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | Feb 14, 2013 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub. | Oct 30, 2017 | Feb 14, 2013 |
| Suse | — | Upgrade xen-kmp-traceUpgrade xen-kmp-paeUpgrade xenUpgrade xen-tools-domUUpgrade xen-kmp-defaultUpgrade xen-develUpgrade xen-libs-32bitUpgrade xen-doc-pdfUpgrade xen-libsUpgrade xen-doc-htmlUpgrade xen-tools | Dec 12, 2013 | Jun 27, 2013 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Feb 14, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub