CVE-2015-8551

Description

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka Linux pciback missing sanity checks.

Risk Information

Base Score
6.0
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.073

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-2846-1) linux-image-3.2.0-97-generic_3.2.0-97.137_i386.debLinux
Linux kernel (USN-2846-1) linux-image-3.2.0-97-generic_3.2.0-97.137_amd64.debLinux
Linux kernel (USN-2846-1) linux-image-3.2.0-97-virtual_3.2.0-97.137_i386.debLinux
Linux kernel (USN-2846-1) linux-image-3.2.0-97-virtual_3.2.0-97.137_amd64.debLinux
Linux kernel (USN-2846-1) linux-image-3.2.0-97-generic-pae_3.2.0-97.137_i386.debLinux
Linux hardware enablement kernel from Trusty (USN-2847-1) linux-image-3.13.0-74-generic_3.13.0-74.118~precise1_i386.debLinux
Linux hardware enablement kernel from Trusty (USN-2847-1) linux-image-3.13.0-74-generic_3.13.0-74.118~precise1_amd64.debLinux
Linux kernel (USN-2848-1) linux-image-3.13.0-74-generic_3.13.0-74.118_i386.debLinux
Linux kernel (USN-2848-1) linux-image-3.13.0-74-generic_3.13.0-74.118_amd64.debLinux
Linux kernel (USN-2848-1) linux-image-3.13.0-74-lowlatency_3.13.0-74.118_i386.debLinux
Linux kernel (USN-2848-1) linux-image-3.13.0-74-lowlatency_3.13.0-74.118_amd64.debLinux
Linux hardware enablement kernel from Utopic (USN-2849-1) linux-image-3.16.0-57-generic_3.16.0-57.77~14.04.1_i386.debLinux
Linux hardware enablement kernel from Utopic (USN-2849-1) linux-image-3.16.0-57-generic_3.16.0-57.77~14.04.1_amd64.debLinux
Linux hardware enablement kernel from Utopic (USN-2849-1) linux-image-3.16.0-57-lowlatency_3.16.0-57.77~14.04.1_i386.debLinux
Linux hardware enablement kernel from Utopic (USN-2849-1) linux-image-3.16.0-57-lowlatency_3.16.0-57.77~14.04.1_amd64.debLinux
Linux kernel (USN-2850-1) linux-image-3.19.0-42-generic_3.19.0-42.48_i386.debLinux
Linux kernel (USN-2850-1) linux-image-3.19.0-42-generic_3.19.0-42.48_amd64.debLinux
Linux kernel (USN-2850-1) linux-image-3.19.0-42-lowlatency_3.19.0-42.48_i386.debLinux
Linux kernel (USN-2850-1) linux-image-3.19.0-42-lowlatency_3.19.0-42.48_amd64.debLinux
Linux hardware enablement kernel from Wily (USN-2853-1) linux-image-4.2.0-22-generic_4.2.0-22.27~14.04.1_i386.debLinux
Linux hardware enablement kernel from Wily (USN-2853-1) linux-image-4.2.0-22-generic_4.2.0-22.27~14.04.1_amd64.debLinux
Linux hardware enablement kernel from Wily (USN-2853-1) linux-image-4.2.0-22-lowlatency_4.2.0-22.27~14.04.1_i386.debLinux
Linux hardware enablement kernel from Wily (USN-2853-1) linux-image-4.2.0-22-lowlatency_4.2.0-22.27~14.04.1_amd64.debLinux
Linux hardware enablement kernel from Vivid (USN-2854-1) linux-image-3.19.0-42-generic_3.19.0-42.48~14.04.1_i386.debLinux
Linux hardware enablement kernel from Vivid (USN-2854-1) linux-image-3.19.0-42-generic_3.19.0-42.48~14.04.1_amd64.debLinux
Linux hardware enablement kernel from Vivid (USN-2854-1) linux-image-3.19.0-42-lowlatency_3.19.0-42.48~14.04.1_i386.debLinux
Linux hardware enablement kernel from Vivid (USN-2854-1) linux-image-3.19.0-42-lowlatency_3.19.0-42.48~14.04.1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234