Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | May 13, 2013 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen. | Oct 30, 2017 | May 13, 2013 |
| Suse | — | Upgrade xen-tools-domUUpgrade xen-kmp-traceUpgrade xen-kmp-defaultUpgrade xenUpgrade xen-libs-32bitUpgrade xen-doc-htmlUpgrade xen-doc-pdfUpgrade sle-sdk-releaseUpgrade xen-develUpgrade xen-toolsUpgrade xen-kmp-paeUpgrade xen-kmp-desktopUpgrade xen-libs | Feb 17, 2015 | May 13, 2013 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | May 13, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub