CVE-2015-8554
published 2016-04-14CVE-2015-8554: Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest…
PriorityP336high7.5CVSS 3.0
AVLACHPRHUINSCCHIHAH
EPSS
0.40%
32.3th percentile
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | <= 4.6.1 | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.6MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj32-x32m-v858: Buffer overflow in hw/pt-msi
ghsa_unreviewed·2022-05-17
CVE-2015-8554 [HIGH] CWE-119 GHSA-jj32-x32m-v858: Buffer overflow in hw/pt-msi
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
OSV
CVE-2015-8554: Buffer overflow in hw/pt-msi
osv·2016-04-14·CVSS 7.5
CVE-2015-8554 [HIGH] CVE-2015-8554: Buffer overflow in hw/pt-msi
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
Red Hat
xen: qemu-dm buffer overrun in MSI-X handling (XSA-164)
vendor_redhat·2015-12-17·CVSS 7.5
CVE-2015-8554 [HIGH] xen: qemu-dm buffer overrun in MSI-X handling (XSA-164)
xen: qemu-dm buffer overrun in MSI-X handling (XSA-164)
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-8554: xen - Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen...
vendor_debian·2015·CVSS 7.5
CVE-2015-8554 [HIGH] CVE-2015-8554: xen - Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen...
Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
bugzilla·2015-12-17·CVSS 4.9
CVE-2015-8554 [MEDIUM] CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
CVE-2015-8554 CVE-2015-8555 CVE-2015-8550 CVE-2015-8551 CVE-2015-8552 CVE-2015-2150 CVE-2015-8553 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2015-8554 xsa164 xen: qemu-dm buffer overrun in MSI-X handling (XSA-164)
bugzilla·2015-12-07·CVSS 7.5
CVE-2015-8554 [HIGH] CVE-2015-8554 xsa164 xen: qemu-dm buffer overrun in MSI-X handling (XSA-164)
CVE-2015-8554 xsa164 xen: qemu-dm buffer overrun in MSI-X handling (XSA-164)
ISSUE DESCRIPTION
"qemu-xen-traditional" (aka qemu-dm) tracks state for each MSI-X table
entry of a passed through device. This is used/updated on
(intercepted) accesses to the page(s) containing the MSI-X table.
There may be space on the final page not covered by any MSI-X table
entry, but memory for state tracking is allocated only for existing
table entries. Therefore bounds checks are required to avoid
accessing/corrupting unrelated heap memory. Such a check is present
for the read path, but was missing for the write path.
IMPACT
A malicious administrator of a guest which has access to a passed
through PCI device which is MSI-X capable can exploit this
vulnerability to take over the qemu process, elevatin
http://support.citrix.com/article/CTX203879http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/79579http://www.securitytracker.com/id/1034481http://xenbits.xen.org/xsa/advisory-164.htmlhttps://security.gentoo.org/glsa/201604-03http://support.citrix.com/article/CTX203879http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/79579http://www.securitytracker.com/id/1034481http://xenbits.xen.org/xsa/advisory-164.htmlhttps://security.gentoo.org/glsa/201604-03
2016-04-14
Published