Access Control Vulnerability in Hypervisor of ACRN Project by ACRN Project
CVE-2020-15687

7.5HIGH

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
31 August 2020

Summary

The Hypervisor component of the ACRN Project is vulnerable due to missing access control restrictions. This flaw permits an attacker with root access in the Service VM userspace to exploit the PCIe assign and de-assign Hypercalls using crafted ioctls and payloads. This manipulation can result in a corrupt state and cause Denial of Service (DoS) for PCIe devices previously assigned to the Service VM at runtime, thereby impacting system stability and availability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-15687 : Access Control Vulnerability in Hypervisor of ACRN Project by ACRN Project | SecurityVulnerability.io