First published: Mon Feb 16 2015(Updated: )
The vgic_v2_to_sgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when running on ARM hardware with general interrupt controller (GIC) version 2, allows local guest users to cause a denial of service (host crash) by writing an invalid value to the GICD.SGIR register.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xen XAPI | =4.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0268 has a high severity level due to its potential for causing denial of service to the host.
To fix CVE-2015-0268, upgrade Xen to a version that addresses this vulnerability, ideally a version later than 4.5.x.
CVE-2015-0268 affects systems running Xen version 4.5.x on ARM hardware with GIC version 2.
CVE-2015-0268 is associated with a denial of service attack that can cause the host to crash.
CVE-2015-0268 requires local guest user access to exploit, therefore it is not a remote vulnerability.