FreeBSD : xen-tools -- Potential unintended writes to host MSI message data field via qemu (af38cfec-27e7-11e5-a4a5-002590263bf5)

Medium Nessus Plugin ID 84711


The remote FreeBSD host is missing a security-related update.


The Xen Project reports :

Logic is in place to avoid writes to certain host config space fields when the guest must nevertheless be able to access their virtual counterparts. A bug in how this logic deals with accesses spanning multiple fields allows the guest to write to the host MSI message data field.

While generally the writes write back the values previously read, their value in config space may have got changed by the host between the qemu read and write. In such a case host side interrupt handling could become confused, possibly losing interrupts or allowing spurious interrupt injection into other guests.

Certain untrusted guest administrators may be able to confuse host side interrupt handling, leading to a Denial of Service.


Update the affected package.

See Also

Plugin Details

Severity: Medium

ID: 84711

File Name: freebsd_pkg_af38cfec27e711e5a4a5002590263bf5.nasl

Version: $Revision: 2.1 $

Type: local

Published: 2015/07/14

Modified: 2015/07/14

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:xen-tools, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2015/07/11

Vulnerability Publication Date: 2015/06/02

Reference Information

CVE: CVE-2015-4103