Denial of Service Risk in ACRN Hypervisor Device Model
CVE-2019-18844

7.5HIGH

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
13 November 2019

Summary

The ACRN Hypervisor's Device Model prior to version 2019w25.5-140000p contains a vulnerability where reliance on assert calls for error propagation may allow an attacker to exploit the PCI core. This could result in denial of service due to assertion failures, compromising the stability of the hypervisor. Mitigations have been implemented in the subsequent updates, addressing the security oversight by enhancing error reporting mechanisms.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.