CVE-2015-0268: Input Validation
The vgicv2tosgi function in arch/arm/vgic-v2.c in Xen 4.5.x, when running on ARM hardware with general interrupt controller (GIC) version 2, allows local guest users to cause a denial of service (host crash) by writing an invalid value to the GICD.SGIR register.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0268?
CVE-2015-0268 has a high severity level due to its potential for causing denial of service to the host.
How do I fix CVE-2015-0268?
To fix CVE-2015-0268, upgrade Xen to a version that addresses this vulnerability, ideally a version later than 4.5.x.
Who is affected by CVE-2015-0268?
CVE-2015-0268 affects systems running Xen version 4.5.x on ARM hardware with GIC version 2.
What type of attack is associated with CVE-2015-0268?
CVE-2015-0268 is associated with a denial of service attack that can cause the host to crash.
Can CVE-2015-0268 be exploited remotely?
CVE-2015-0268 requires local guest user access to exploit, therefore it is not a remote vulnerability.