CVE-2015-4104 — Deserialization of Untrusted Data in Qemu
CWE-264CWE-502 — Deserialization of Untrusted DataCWE-20 — Improper Input Validation13 documents8 sources
Severity
7.8HIGHNVD
GHSA10.0GHSA7.5OSV7.5
EPSS
8.4%
top 7.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateMay 17
Description
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
CVSS vector
AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9