Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-8552


The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."


Published

2016-04-13T15:59:06.257

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 4.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:S/C:N/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.1

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System xen xen 3.1.3 Yes
Operating System xen xen 3.1.4 Yes
Operating System xen xen 3.2.0 Yes
Operating System xen xen 3.2.1 Yes
Operating System xen xen 3.2.2 Yes
Operating System xen xen 3.2.3 Yes
Operating System xen xen 3.3.0 Yes
Operating System xen xen 3.3.1 Yes
Operating System xen xen 3.3.2 Yes
Operating System xen xen 3.4.0 Yes
Operating System xen xen 3.4.1 Yes
Operating System xen xen 3.4.2 Yes
Operating System xen xen 3.4.3 Yes
Operating System xen xen 3.4.4 Yes
Operating System xen xen 4.0.0 Yes
Operating System xen xen 4.0.1 Yes
Operating System xen xen 4.0.2 Yes
Operating System xen xen 4.0.3 Yes
Operating System xen xen 4.0.4 Yes
Operating System xen xen 4.1.0 Yes
Operating System xen xen 4.1.1 Yes
Operating System xen xen 4.1.2 Yes
Operating System xen xen 4.1.3 Yes
Operating System xen xen 4.1.4 Yes
Operating System xen xen 4.1.5 Yes
Operating System xen xen 4.1.6 Yes
Operating System xen xen 4.1.6.1 Yes
Operating System xen xen 4.2.0 Yes
Operating System xen xen 4.2.1 Yes
Operating System xen xen 4.2.2 Yes
Operating System xen xen 4.2.3 Yes
Operating System xen xen 4.2.4 Yes
Operating System xen xen 4.2.5 Yes
Operating System xen xen 4.3.0 Yes
Operating System xen xen 4.3.1 Yes
Operating System xen xen 4.3.2 Yes
Operating System xen xen 4.3.3 Yes
Operating System xen xen 4.3.4 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System debian debian_linux 6.0 Yes
Operating System novell suse_linux_enterprise_debuginfo 11 Yes
Operating System novell suse_linux_enterprise_real_time_extension 11 Yes
Operating System novell suse_linux_enterprise_real_time_extension 12 Yes

References