CVE-2015-8551
Last modified
CVE-2015-8551 is a medium-severity vulnerability rated 6/10 on the CVSS scale. The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks.". EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks."
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 3.1, <= 3.1.10 | — |
| Linux | Linux Kernel | >= 4.3.0, <= 4.3.6 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Opensuse | Opensuse | 13.1 | — |
| Suse | Linux Enterprise Desktop | 11 | Sp4 |
| Suse | Linux Enterprise Desktop | 12 | Sp1 |
| Suse | Linux Enterprise Real Time Extension | 11 | Sp4 |
| Suse | Linux Enterprise Real Time Extension | 12 | Sp1 |
| Suse | Linux Enterprise Server | 11 | — |
| Suse | Linux Enterprise Server | 12 | Sp1 |
| Suse | Linux Enterprise Software Development Kit | 11 | Sp4 |
| Suse | Linux Enterprise Software Development Kit | 12 | Sp1 |
| Suse | Linux Enterprise Workstation Extension | 12 | Sp1 |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3434Third Party Advisory
- http://www.securityfocus.com/bid/79546Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034480Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-157.htmlVendor Advisory
- https://security.gentoo.org/glsa/201604-03Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3434Third Party Advisory
- http://www.securityfocus.com/bid/79546Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034480Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-157.htmlVendor Advisory
- https://security.gentoo.org/glsa/201604-03Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8551?
How severe is CVE-2015-8551?
How do I fix CVE-2015-8551?
Are you affected by CVE-2015-8551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
