CVE-2011-3131
published 2012-12-13CVE-2011-3131: Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many…
PriorityP415medium4.6CVSS 2.0
AVLACLAuSCNINAC
EPSS
0.44%
35.6th percentile
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.2-1 (bookworm) | xen 4.1.2-1 (bookworm) |
| xen | xen | <= 4.1.1 | — |
| xen | xen | >= 0 < 4.1.2-1 | 4.1.2-1 |
| xen | xen | >= 0 < 4.1.2-1 | 4.1.2-1 |
| xen | xen | >= 0 < 4.1.2-1 | 4.1.2-1 |
| xen | xen | >= 0 < 4.1.2-1 | 4.1.2-1 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xen: IOMMU fault livelock
vendor_redhat·2011-08-12·CVSS 4.6
CVE-2011-3131 [MEDIUM] kernel: xen: IOMMU fault livelock
kernel: xen: IOMMU fault livelock
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
Statement: The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6,
and Red Hat Enterprise MRG are not affected. It has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
Debian
CVE-2011-3131: xen - Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] dev...
vendor_debian·2011·CVSS 4.6
CVE-2011-3131 [MEDIUM] CVE-2011-3131: xen - Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] dev...
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
Scope: local
bookworm: resolved (fixed in 4.1.2-1)
bullseye: resolved (fixed in 4.1.2-1)
forky: resolved (fixed in 4.1.2-1)
sid: resolved (fixed in 4.1.2-1)
trixie: resolved (fixed in 4.1.2-1)
GHSA
GHSA-86mp-q3fq-9h73: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2011-3131 [MEDIUM] GHSA-86mp-q3fq-9h73: Xen 4
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
OSV
CVE-2011-3131: Xen 4
osv·2012-12-13·CVSS 4.6
CVE-2011-3131 [MEDIUM] CVE-2011-3131: Xen 4
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
No detection rules found.
No public exploits indexed.
http://old-list-archives.xen.org/archives/html/xen-devel/2011-06/msg01106.htmlhttp://old-list-archives.xen.org/archives/html/xen-devel/2011-08/msg00450.htmlhttp://secunia.com/advisories/45622http://secunia.com/advisories/51468http://www.debian.org/security/2012/dsa-2582http://www.securityfocus.com/bid/49146http://xenbits.xen.org/hg/staging/xen-4.1-testing.hg/rev/84e3706df07ahttp://old-list-archives.xen.org/archives/html/xen-devel/2011-06/msg01106.htmlhttp://old-list-archives.xen.org/archives/html/xen-devel/2011-08/msg00450.htmlhttp://secunia.com/advisories/45622http://secunia.com/advisories/51468http://www.debian.org/security/2012/dsa-2582http://www.securityfocus.com/bid/49146http://xenbits.xen.org/hg/staging/xen-4.1-testing.hg/rev/84e3706df07a
2012-12-13
Published