CVE-2015-2150
published 2015-03-12CVE-2015-2150: Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to…
PriorityP419medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.53%
41.4th percentile
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt9-1 (bookworm) | linux 3.16.7-ckt9-1 (bookworm) |
| linux | linux_kernel | <= 3.19.1 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.13.0-53.88 | 3.13.0-53.88 |
| ubuntu | ubuntu | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_redhat7.1HIGH
vendor_debian4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7jv-fgrf-v497: Xen 3
ghsa_unreviewed·2022-05-14
CVE-2015-2150 [MEDIUM] GHSA-w7jv-fgrf-v497: Xen 3
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
OSV
linux vulnerabilities
osv·2015-05-20·CVSS 4.9
CVE-2014-9715 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Vincent Tondellier discovered an integer overflow in the Linux kernel's
netfilter connection tracking accounting of loaded extensions. An attacker
on the local area network (LAN) could potential exploit this flaw to cause
a denial of service (system crash of targeted system). (CVE-2014-9715)
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A privilege escalation was discovered in the fork syscall via the int80 entry
on 64 bit kernels with 32 bit emulation support. An unprivileged local
attacker could exploit this flaw to increase their privileges on the
system. (CVE-2015-2830)
A
OSV
linux-lts-utopic vulnerabilities
osv·2015-04-30·CVSS 4.9
CVE-2015-2150 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker could exploit this flaw to increase their privileges on the
system. (CVE-2015-2830)
It was discovered that the Linux kernel
OSV
CVE-2015-2150: Xen 3
osv·2015-03-12·CVSS 4.9
CVE-2015-2150 [MEDIUM] CVE-2015-2150: Xen 3
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Kernel
xen-pciback: limit guest control of command register
kernel_security·2015-03-11·CVSS 4.9
CVE-2015-2150 [MEDIUM] xen-pciback: limit guest control of command register
xen-pciback: limit guest control of command register
Otherwise the guest can abuse that control to cause e.g. PCIe
Unsupported Request responses by disabling memory and/or I/O decoding
and subsequently causing (CPU side) accesses to the respective address
ranges, which (depending on system configuration) may be fatal to the
host.
Note that to alter any of the bits collected together as
PCI_COMMAND_GUEST permissive mode is now required to be enabled
globally or on the specific device.
This is CVE-2015-2150 / XSA-120.
Signed-off-by: Jan Beulich
Reviewed-by: Konrad Rzeszutek Wilk
Cc:
Signed-off-by: David Vrabel
Red Hat
spice: Host memory access from guest with invalid primary surface parameters
vendor_redhat·2016-06-06·CVSS 7.1
CVE-2016-2150 [HIGH] spice: Host memory access from guest with invalid primary surface parameters
spice: Host memory access from guest with invalid primary surface parameters
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
A memory access flaw was found in the way spice handled certain guests using crafted primary surface parameters. A user in a guest could use this flaw to read from and write to arbitrary memory locations on the host.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-06-10·CVSS 4.9
CVE-2015-2150 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker could exploit this flaw to increase their privileges on the
system. (CVE-2015-2830)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially escalate
p
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-06-10·CVSS 4.9
CVE-2015-2150 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker could exploit this flaw to increase their privileges on the
system. (CVE-2015-2830)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially es
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-05-20·CVSS 4.9
CVE-2014-9715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vincent Tondellier discovered an integer overflow in the Linux kernel's
netfilter connection tracking accounting of loaded extensions. An attacker
on the local area network (LAN) could potential exploit this flaw to cause
a denial of service (system crash of targeted system). (CVE-2014-9715)
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A privilege escalation was discovered in the fork syscall via the int80 entry
on 64 bit kernels with 32 bit emulation support. An unprivileged local
attacker could exploi
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-05-20·CVSS 4.9
CVE-2014-9715 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vincent Tondellier discovered an integer overflow in the Linux kernel's
netfilter connection tracking accounting of loaded extensions. An attacker
on the local area network (LAN) could potential exploit this flaw to cause
a denial of service (system crash of targeted system). (CVE-2014-9715)
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 4.9
CVE-2015-2150 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
A privilege escalation was discovered in the fork syscal vi the int80 entry
on 64 bit kernels with 32 bit emulation support. An unprivileged local
attacker could exploit this flaw to increase their privileges on the
sys
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 4.9
CVE-2015-2150 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered the Xen virtual machine subsystem of the Linux
kernel did not properly restrict access to PCI command registers. A local
guest user could exploit this flaw to cause a denial of service (host
crash). (CVE-2015-2150)
A stack overflow was discovered in the the microcode loader for the intel
x86 platform. A local attacker could exploit this flaw to cause a denial of
service (kernel crash) or to potentially execute code with kernel
privileges. (CVE-2015-2666)
A privilege escalation was discovered in the fork syscall via the int80
entry on 64 bit kernels with 32 bit emulation support. An unprivileged
local attacker could exploit this flaw to increase their privil
Red Hat
xen: non-maskable interrupts triggerable by guests (xsa120)
vendor_redhat·2015-03-10·CVSS 4.9
CVE-2015-2150 [MEDIUM] xen: non-maskable interrupts triggerable by guests (xsa120)
xen: non-maskable interrupts triggerable by guests (xsa120)
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Statement: This issue does affect the Dom0 Xen kernel as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to th
Debian
CVE-2015-2150: linux - Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly rest...
vendor_debian·2015·CVSS 4.9
CVE-2015-2150 [MEDIUM] CVE-2015-2150: linux - Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly rest...
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt9-1)
bullseye: resolved (fixed in 3.16.7-ckt9-1)
forky: resolved (fixed in 3.16.7-ckt9-1)
sid: resolved (fixed in 3.16.7-ckt9-1)
trixie: resolved (fixed in 3.16.7-ckt9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
bugzilla·2016-03-01·CVSS 7.1
CVE-2016-2150 [HIGH] CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
It was found that one malicious guest inside a virtual machine can take control of the corresponding Qemu process in the host using crafted primary surface parameters. This issue is similar to CVE-2015-5261, but it's using different path in the code.
Discussion:
Acknowledgments:
Name: Frediano Ziglio (Red Hat)
---
Created spice tracking bugs for this issue:
Affects: fedora-all [bug 1343135]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1205 https://access.redhat.com/errata/RHSA-2016:1205
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1204 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
bugzilla·2015-12-17·CVSS 4.9
CVE-2015-8554 [MEDIUM] CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2015-2150 CVE-2015-8553 kernel: xen: non-maskable interrupts triggerable by guests (xsa120) [fedora-all]
bugzilla·2015-03-10·CVSS 4.9
CVE-2015-2150 [MEDIUM] CVE-2015-2150 CVE-2015-8553 kernel: xen: non-maskable interrupts triggerable by guests (xsa120) [fedora-all]
CVE-2015-2150 CVE-2015-8553 kernel: xen: non-maskable interrupts triggerable by guests (xsa120) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2015-2150 CVE-2015-8553 xen: non-maskable interrupts triggerable by guests (xsa120)
bugzilla·2015-02-25·CVSS 4.9
CVE-2015-2150 [MEDIUM] CVE-2015-2150 CVE-2015-8553 xen: non-maskable interrupts triggerable by guests (xsa120)
CVE-2015-2150 CVE-2015-8553 xen: non-maskable interrupts triggerable by guests (xsa120)
ISSUE DESCRIPTION
Guests are currently permitted to modify all of the (writable) bits in
the PCI command register of devices passed through to them. This in
particular allows them to disable memory and I/O decoding on the
device unless the device is an SR-IOV virtual function, in which case
subsequent accesses to the respective MMIO or I/O port ranges would
- - on PCI Express devices - lead to Unsupported Request responses. The
treatmeant of such errors is platform specific.
IMPACT
In the event that the platform surfaces aforementioned UR responses as
Non-Maskable Interrupts, and either the OS is configured to treat NMIs
as fatal or (e.g. via ACPI's APEI) the platform tells the OS to treat
these err
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=af6fc858a35b90e89ea7a7ee58e66628c55c776bhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155804.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155854.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155908.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152747.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/73014http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031902http://www.ubuntu.com/usn/USN-2631-1http://www.ubuntu.com/usn/USN-2632-1http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htmhttp://xenbits.xen.org/xsa/advisory-120.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1196266https://github.com/torvalds/linux/commit/af6fc858a35b90e89ea7a7ee58e66628c55c776bhttps://seclists.org/bugtraq/2019/Aug/18http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=af6fc858a35b90e89ea7a7ee58e66628c55c776bhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155804.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155854.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155908.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152747.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00021.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/73014http://www.securitytracker.com/id/1031806http://www.securitytracker.com/id/1031902http://www.ubuntu.com/usn/USN-2631-1http://www.ubuntu.com/usn/USN-2632-1http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-423503.htmhttp://xenbits.xen.org/xsa/advisory-120.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1196266https://github.com/torvalds/linux/commit/af6fc858a35b90e89ea7a7ee58e66628c55c776bhttps://seclists.org/bugtraq/2019/Aug/18
2015-03-12
Published