CVE-2015-2150
Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
- Affected products
- Alt Linux, Linux Kernel, Suse, Ubuntu, Xen
- Ubuntu
- = 12.04
- Fix
- Available
- CVSS 2.0
- 4.9 MEDIUM
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2015-03-12
CVE-2015-2150 at NVD
No indexed exploits for CVE-2015-2150 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-2150 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.