CVE-2015-4104
published 2015-06-03CVE-2015-4104: Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected…
PriorityP334high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.43%
87.6th percentile
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:2.3+dfsg-5 (bookworm) | qemu 1:2.3+dfsg-5 (bookworm) |
| debian | xen | < qemu 1:2.3+dfsg-5 (bookworm) | qemu 1:2.3+dfsg-5 (bookworm) |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.3+dfsg-5 | 1:2.3+dfsg-5 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.13 | 2.0.0+dfsg-2ubuntu1.13 |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
ghsa10.0CRITICAL
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mcww-78xg-3cx3: Xen 3
ghsa_unreviewed·2022-05-17
CVE-2015-4104 [HIGH] GHSA-mcww-78xg-3cx3: Xen 3
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
GHSA
Deserialization of Untrusted Data in Log4j 1.x
ghsa·2022-01-21·CVSS 7.5
CVE-2022-23302 [HIGH] CWE-502 Deserialization of Untrusted Data in Log4j 1.x
Deserialization of Untrusted Data in Log4j 1.x
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
GHSA
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
ghsa·2021-12-14·CVSS 10.0
CVE-2021-4104 [CRITICAL] CWE-502 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
OSV
qemu, qemu-kvm vulnerabilities
osv·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] qemu, qemu-kvm vulnerabilities
qemu, qemu-kvm vulnerabilities
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of service. This issue only applied to Ubuntu 14.04
LTS, U
OSV
CVE-2015-4104: Xen 3
osv·2015-06-03·CVSS 7.8
CVE-2015-4104 [HIGH] CVE-2015-4104: Xen 3
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2015-06-10·CVSS 7.5
CVE-2015-3209 [HIGH] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Matt Tait discovered that QEMU incorrectly handled the virtual PCNET
driver. A malicious guest could use this issue to cause a denial of
service, or possibly execute arbitrary code on the host as the user running
the QEMU process. In the default installation, when QEMU is used with
libvirt, attackers would be isolated by the libvirt AppArmor profile.
(CVE-2015-3209)
Kurt Seifried discovered that QEMU incorrectly handled certain temporary
files. A local attacker could use this issue to cause a denial of service.
(CVE-2015-4037)
Jan Beulich discovered that the QEMU Xen code incorrectly restricted write
access to the host MSI message data field. A malicious guest could use this
issue to cause a denial of serv
Red Hat
xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129)
vendor_redhat·2015-06-02·CVSS 7.8
CVE-2015-4104 [HIGH] xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129)
xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129)
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
Statement: This issue does affect then Xen packages as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: xen (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2015-4104: qemu - Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, ...
vendor_debian·2015·CVSS 7.8
CVE-2015-4104 [HIGH] CVE-2015-4104: qemu - Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, ...
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:2.3+dfsg-5)
bullseye: resolved (fixed in 1:2.3+dfsg-5)
forky: resolved (fixed in 1:2.3+dfsg-5)
sid: resolved (fixed in 1:2.3+dfsg-5)
trixie: resolved (fixed in 1:2.3+dfsg-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4104 xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129) [fedora-all]
bugzilla·2015-06-03·CVSS 7.8
CVE-2015-4104 [HIGH] CVE-2015-4104 xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129) [fedora-all]
CVE-2015-4104 xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2015-4104 xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129)
bugzilla·2015-05-21·CVSS 7.8
CVE-2015-4104 [HIGH] CVE-2015-4104 xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129)
CVE-2015-4104 xen: PCI MSI mask bits inadvertently exposed to guests (xsa-129)
ISSUE DESCRIPTION
The mask bits optionally available in the PCI MSI capability structure are used by the hypervisor to occasionally suppress interrupt delivery. Unprivileged guests were, however, nevertheless allowed direct control of these bits.
IMPACT
Interrupts may be observed by Xen at unexpected times, which may lead to a host crash and therefore a Denial of Service.
VULNERABLE SYSTEMS
Xen versions 3.3 and onwards are vulnerable due to supporting PCI pass-through.
Only x86 systems are vulnerable. ARM systems are not vulnerable.
Only HVM guests with their device model run in Dom0 can take advantage of this vulnerability.
Only HVM guests which have been granted access to physical PCI devices (`PCI pa
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160154.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160171.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/74950http://www.securitytracker.com/id/1032464http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-129.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160154.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160171.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/160685.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.htmlhttp://support.citrix.com/article/CTX201145http://www.debian.org/security/2015/dsa-3284http://www.debian.org/security/2015/dsa-3286http://www.securityfocus.com/bid/74950http://www.securitytracker.com/id/1032464http://www.ubuntu.com/usn/USN-2630-1http://xenbits.xen.org/xsa/advisory-129.htmlhttps://security.gentoo.org/glsa/201604-03https://support.citrix.com/article/CTX206006
2015-06-03
Published