CVE-2013-3495: Medium severity opensuse vulnerability
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3495?
CVE-2013-3495 is rated as a high severity vulnerability due to its potential to cause kernel panic and denial of service.
How do I fix CVE-2013-3495?
To fix CVE-2013-3495, upgrade to a patched version of Xen or apply the relevant updates provided by your distribution.
What versions of Xen are affected by CVE-2013-3495?
CVE-2013-3495 affects Xen versions from 3.3.x through 4.3.x, including specific versions like 3.3.1, 4.1.5, and others.
How can CVE-2013-3495 be exploited?
CVE-2013-3495 can be exploited by local guests sending a malformed Message Signaled Interrupt (MSI) from a bus mastering capable PCI device.
What are the consequences of CVE-2013-3495 exploitation?
Exploiting CVE-2013-3495 can lead to a denial of service condition resulting in a kernel panic, impacting the stability of the host system.