Lucene search

K
nvd[email protected]NVD:CVE-2011-4347
HistoryJun 08, 2013 - 1:05 p.m.

CVE-2011-4347

2013-06-0813:05:55
CWE-264
web.nvd.nist.gov
1

4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:N/I:N/A:C

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.3%

The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM_ASSIGN_PCI_DEVICE operation.

Affected configurations

NVD
Node
linuxlinux_kernelRange3.1.9
OR
linuxlinux_kernelMatch3.1.1
OR
linuxlinux_kernelMatch3.1.2
OR
linuxlinux_kernelMatch3.1.3
OR
linuxlinux_kernelMatch3.1.4
OR
linuxlinux_kernelMatch3.1.5
OR
linuxlinux_kernelMatch3.1.6
OR
linuxlinux_kernelMatch3.1.7
OR
linuxlinux_kernelMatch3.1.8

4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:N/I:N/A:C

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.3%