MEDIUM
kernel: xen: IOMMU fault livelock
Published Dec 13, 2012
4.6
MEDIUMCVSS 2.0
EPSS 0.44%
Description
Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
Affected products
Remediation
Red Hat statement
The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 4, 6, and Red Hat Enterprise MRG are not affected. It has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2011-1386.html.
Weaknesses (1)
References (12)
- http://old-list-archives.xen.org/archives/html/xen-devel/2011-06/msg01106.html mailing-listx_refsource_MLIST
- http://old-list-archives.xen.org/archives/html/xen-devel/2011-08/msg00450.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/45622 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/51468 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2012/dsa-2582 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/49146 vdb-entryx_refsource_BID
- http://xenbits.xen.org/hg/staging/xen-4.1-testing.hg/rev/84e3706df07a x_refsource_CONFIRMExploit
- https://access.redhat.com/security/cve/CVE-2011-3131 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=730341 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-3099 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-3131
- https://www.cve.org/CVERecord?id=CVE-2011-3131
| Link | Providers | Tags |
|---|---|---|
| http://old-list-archives.xen.org/archives/html/xen-devel/2011-06/msg01106.html | mailing-listx_refsource_MLIST | |
| http://old-list-archives.xen.org/archives/html/xen-devel/2011-08/msg00450.html | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/45622 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/51468 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.debian.org/security/2012/dsa-2582 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/49146 | vdb-entryx_refsource_BID | |
| http://xenbits.xen.org/hg/staging/xen-4.1-testing.hg/rev/84e3706df07a | x_refsource_CONFIRMExploit | |
| https://access.redhat.com/security/cve/CVE-2011-3131 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=730341 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-3099 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2011-3131 | ||
| https://www.cve.org/CVERecord?id=CVE-2011-3131 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 13, 2012
Updated Sep 16, 2024
Reserved Aug 11, 2011
Link CVE-2011-3131
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2011-3099 Assigner mitre
Published Dec 13, 2012
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2011-3099