CVE Vulnerabilities

CVE-2020-15687

Published: Aug 31, 2020 | Modified: Sep 08, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This attack results in a corrupt state and Denial of Service (DoS) for previously assigned PCIe devices to the Service VM at runtime.

Affected Software

Name Vendor Start Version End Version
Acrn Linuxfoundation 1.6.1 (including) 1.6.1 (including)
Acrn Linuxfoundation 2.0 (including) 2.0 (including)

References