shuox/acrn-hypervisor

shuox/acrn-hypervisor

Releases2
Frequency5 hours
Last Release
Project ACRN hypervisor

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of service (assertion failure) within pci core. This is fixed in 1.2. 6199e653418e is a mitigation for pre-1.1 versions, whereas 2b3dedfb9ba1 is a mitigation for 1.1.