Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-2150
HistoryMar 12, 2015 - 12:00 a.m.

CVE-2015-2150

2015-03-1200:00:00
ubuntu.com
ubuntu.com
31

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.001 Low

EPSS

Percentile

28.1%

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly
restrict access to PCI command registers, which might allow local guest OS
users to cause a denial of service (non-maskable interrupt and host crash)
by disabling the (1) memory or (2) I/O decoding for a PCI Express device
and then accessing the device, which triggers an Unsupported Request (UR)
response.

Bugs

Notes

Author Note
jdstrand android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.10 and earlier preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchlinux< 3.2.0-85.122UNKNOWN
ubuntu14.04noarchlinux< 3.13.0-53.88UNKNOWN
ubuntu14.10noarchlinux< 3.16.0-36.48UNKNOWN
ubuntu12.04noarchlinux-armadaxp< 3.2.0-1651.71UNKNOWN
ubuntu12.04noarchlinux-lts-trusty< 3.13.0-53.87~precise1UNKNOWN
ubuntu14.04noarchlinux-lts-utopic< 3.16.0-36.48~14.04.1UNKNOWN
ubuntu12.04noarchlinux-ti-omap4< 3.2.0-1465.85UNKNOWN

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

0.001 Low

EPSS

Percentile

28.1%