ISSUE DESCRIPTION ================= When decoding a guest write to a specific register in the virtual interrupt controller Xen would treat an invalid value as a critical error and crash the host. IMPACT ====== By writing an invalid value to the GICD.SGIR register a guest can crash the host, resulting in a Denial of Service attack. VULNERABLE SYSTEMS ================== Xen 4.5 and later systems running on ARM hardware with version 2 of the generic interrupt controller are vulnerable. Systems running on ARM hardware with version 3 of the generic interrupt controller are not vulnerable. x86 systems are not affected. Statement: This issue did not affect the versions of xen as shipped with Red Hat Enterprise Linux 5. Acknowledgements: Red Hat would like to thank the Xen project for reporting this issue.
This is now public: http://seclists.org/oss-sec/2015/q1/534
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1194675]