CVE-2015-4103
published 2015-06-03CVE-2015-4103: Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.45%
36.4th percentile
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.3+dfsg-5 (bookworm) | qemu 1:2.3+dfsg-5 (bookworm) |
| debian | xen | < qemu 1:2.3+dfsg-5 (bookworm) | qemu 1:2.3+dfsg-5 (bookworm) |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.13 | 2.0.0+dfsg-2ubuntu1.13 |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of serv
Red Hat
xen: potential unintended writes to host MSI message data field via qemu (xsa-128)
vendor_redhat·2015-06-02·CVSS 4.9
CVE-2015-4103 [MEDIUM] xen: potential unintended writes to host MSI message data field via qemu (xsa-128)
xen: potential unintended writes to host MSI message data field via qemu (xsa-128)
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
Statement: This issue does affect then Xen packages as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/update
Debian
CVE-2015-4103: qemu - Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI ...
vendor_debian·2015·CVSS 4.9
CVE-2015-4103 [MEDIUM] CVE-2015-4103: qemu - Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI ...
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-5)
bullseye: resolved (fixed in 1:2.3+dfsg-5)
forky: resolved (fixed in 1:2.3+dfsg-5)
sid: resolved (fixed in 1:2.3+dfsg-5)
trixie: resolved (fixed in 1:2.3+dfsg-5)
GHSA
GHSA-pgcx-wwx7-v778: Xen 3
ghsa_unreviewed·2022-05-17
CVE-2015-4103 [MEDIUM] GHSA-pgcx-wwx7-v778: Xen 3
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of service. This issue only applied to Ubuntu 14.04
LTS, U
OSV
CVE-2015-4103: Xen 3
osv·2015-06-03·CVSS 4.9
CVE-2015-4103 [MEDIUM] CVE-2015-4103: Xen 3
Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4103 xen: potential unintended writes to host MSI message data field via qemu (xsa-128) [fedora-all]
bugzilla·2015-06-03·CVSS 4.9
CVE-2015-4103 [MEDIUM] CVE-2015-4103 xen: potential unintended writes to host MSI message data field via qemu (xsa-128) [fedora-all]
CVE-2015-4103 xen: potential unintended writes to host MSI message data field via qemu (xsa-128) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2015-4103 xen: potential unintended writes to host MSI message data field via qemu (xsa-128)
bugzilla·2015-05-21·CVSS 4.9
CVE-2015-4103 [MEDIUM] CVE-2015-4103 xen: potential unintended writes to host MSI message data field via qemu (xsa-128)
CVE-2015-4103 xen: potential unintended writes to host MSI message data field via qemu (xsa-128)
ISSUE DESCRIPTION
Logic is in place to avoid writes to certain host config space fields when the guest must nevertheless be able to access their virtual counterparts. A bug in how this logic deals with accesses spanning multiple fields allows the guest to write to the host MSI message data field.
While generally the writes write back the values previously read, their value in config space may have got changed by the host between the qemu read and write. In such a case host side interrupt handling could become confused, possibly losing interrupts or allowing spurious interrupt injection into other guests.
IMPACT
Certain untrusted guest administrators may be able to confuse host side interru
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160154.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160171.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/74947http://www.securitytracker.com/id/1032456http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-128.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160154.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160171.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/74947http://www.securitytracker.com/id/1032456http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-128.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006
2015-06-03
Published