CVE-2012-5634: Medium severity xen xapi vulnerability
Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5634?
The severity of CVE-2012-5634 is considered to be medium due to its potential to cause a denial of service.
How do I fix CVE-2012-5634?
To fix CVE-2012-5634, upgrade to a version of Xen that is not affected, specifically versions later than 4.2.1.
What type of attack does CVE-2012-5634 allow?
CVE-2012-5634 allows local guests to perform a denial of service attack against other guests.
Which versions of Xen are affected by CVE-2012-5634?
Xen versions 4.0.0, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.2.0, and 4.2.1 are affected by CVE-2012-5634.
What is the underlying cause of CVE-2012-5634?
The underlying cause of CVE-2012-5634 is improper configuration of Intel VT-d related to PCI passthrough when using a legacy PCI Bridge.