CVE-2015-2150

Ubuntu < 3.19.1 - Access Control

Title source: rule
STIX 2.1

Description

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

References (21)

Core 21
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2631-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2632-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155908.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155804.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3237
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155854.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1196266
Vendor Advisory x_refsource_confirm
http://xenbits.xen.org/xsa/advisory-120.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031902
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152747.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73014
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031806
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Aug/18

Scores

EPSS 0.0011
EPSS Percentile 28.8%

Details

CWE
CWE-264
Status published
Products (31)
linux/linux_kernel < 3.19.1
ubuntu/ubuntu 12.04
xen/xen 3.3.0
xen/xen 3.3.1
xen/xen 3.3.2
xen/xen 3.4.0
xen/xen 3.4.1
xen/xen 3.4.2
xen/xen 3.4.3
xen/xen 3.4.4
... and 21 more
Published Mar 12, 2015
Tracked Since Feb 18, 2026