Vulnerability Name:

CVE-2011-3131 (CCN-69179)

Assigned:2011-08-12
Published:2011-08-12
Updated:2012-12-13
Summary:Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.
CVSS v3 Severity:6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
5.2 Medium (REDHAT CVSS v2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C)
3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:A/AC:M/Au:S/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2011-3131

Source: CCN
Type: Xen-devel Mailing List, Thu, 16 Jun 2011 10:25:09 +0100
IOMMU faults

Source: CCN
Type: Xen-devel Mailing List, Fri, 12 Aug 2011 14:27:53 +0100
Xen Advisory 5 (CVE-2011-3131) IOMMU fault livelock

Source: MLIST
Type: UNKNOWN
[Xen-devel] 20110616 IOMMU faults

Source: MLIST
Type: UNKNOWN
[Xen-devel] 20110812 Xen Advisory 5 (CVE-2011-3131) IOMMU fault livelock

Source: CCN
Type: RHSA-2011-1386
Important: kernel security, bug fix, and enhancement update

Source: CCN
Type: SA45622
Xen DMA Requests IOMMU Denial of Service Weakness

Source: SECUNIA
Type: Vendor Advisory
45622

Source: CCN
Type: SA46105
Xen DMA Requests IOMMU Denial of Service Weakness

Source: SECUNIA
Type: Vendor Advisory
51468

Source: DEBIAN
Type: UNKNOWN
DSA-2582

Source: DEBIAN
Type: DSA-2582
xen -- several vulnerabilities

Source: CCN
Type: OSVDB ID: 74629
Xen DMA Request Parsing IOMMU Fault Local DoS

Source: BID
Type: UNKNOWN
49146

Source: CCN
Type: BID-49146
Xen DMA Requests IOMMU Denial of Service Vulnerability

Source: CONFIRM
Type: Exploit
http://xenbits.xen.org/hg/staging/xen-4.1-testing.hg/rev/84e3706df07a

Source: CCN
Type: Xen Mercurial Repository
Xen

Source: XF
Type: UNKNOWN
xen-dma-dos(69179)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:xen:xen:*:*:*:*:*:*:*:* (Version <= 4.1.1)

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20113131
    V
    CVE-2011-3131
    2022-05-20
    oval:org.mitre.oval:def:20155
    P
    DSA-2582-1 xen - denial of service
    2014-06-23
    oval:org.mitre.oval:def:23388
    P
    ELSA-2011:1386: kernel security, bug fix, and enhancement update (Important)
    2014-05-26
    oval:org.mitre.oval:def:21885
    P
    RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)
    2014-02-24
    oval:com.ubuntu.precise:def:20113131000
    V
    CVE-2011-3131 on Ubuntu 12.04 LTS (precise) - low.
    2012-12-13
    oval:com.redhat.rhsa:def:20111386
    P
    RHSA-2011:1386: kernel security, bug fix, and enhancement update (Important)
    2011-10-20
    BACK
    xen xen *