CVE-2011-1898: High severity Citrix Xen vulnerability
Problem description: Intel VT-d chipsets without interrupt remapping do not prevent a guest which owns a PCI device from using DMA to generate MSI interrupts by writing to the interrupt injection registers. This can be exploited to inject traps and gain control of the host.
References: http://lists.xensource.com/archives/html/xen-devel/2011-05/msg00687.html http://theinvisiblethings.blogspot.com/2011/05/following-white-rabbit-software-attacks.html http://www.invisiblethingslab.com/resources/2011/Software%20Attacks%20on%20Intel%20VT-d.pdf
Other sources
Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by "using DMA to generate MSI interrupts by writing to the interrupt injection registers."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1898?
CVE-2011-1898 is categorized as a critical vulnerability due to the potential for an attacker to gain control of the host system.
How do I fix CVE-2011-1898?
To mitigate CVE-2011-1898, upgrade to Xen versions that implement interrupt remapping and ensure your chipset supports this feature.
Which software versions are affected by CVE-2011-1898?
CVE-2011-1898 affects Citrix Xen versions 4.0.0, 4.0.1, and 4.1.0.
What type of attack does CVE-2011-1898 enable?
CVE-2011-1898 enables a Guest-to-Host privilege escalation attack through unauthorized interrupt injection.
Is hardware configuration relevant to CVE-2011-1898?
Yes, the vulnerability is specifically related to Intel VT-d chipsets that lack interrupt remapping capabilities.