6

CVE-2015-8551

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.1 <= 3.1.10
Linux ≫ Linux Kernel Version >= 4.3.0 <= 4.3.6
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Opensuse ≫ Opensuse Version 13.1
Suse ≫ Linux Enterprise Desktop Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp4
Suse ≫ Linux Enterprise Real Time Extension Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 11 Update -
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
NIST 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://security.gentoo.org/glsa/201604-03
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html
Third Party Advisory
Mailing List
http://www.debian.org/security/2016/dsa-3434
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00059.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/79546
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034480
Third Party Advisory
VDB Entry
http://xenbits.xen.org/xsa/advisory-157.html
Vendor Advisory