Release date:
Updated on:
Affected Systems:
XenSource Xen 4.1.2
XenSource Xen 4.1.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57223
CVE (CAN) ID: CVE-2012-5634
Xen is an open-source Virtual Machine monitor developed by the University of Cambridge.
The Xen 4.1.x function "set_msi_source_id ()" (drivers/passthrough/vtd/intremap. c) there is an error in dealing with VT-d interruptions, which can be exploited to inject an erroneous interruption and cause a crash. To successfully exploit this vulnerability, you must use Intel VT-d for PCI passthrough.
<* Source: Xen.org security team (security@xen.org)
Link: http://www.securelist.com/en/advisories/51734
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XenSource
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://xen.xensource.com/