Vigil@nce - Xen: hardware access on ARM
May 2014 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker, who is located in a guest system, can use
vulnerabilities in the ARM implementation of Xen, in order to
trigger a denial of service, and possibly to execute code.
– Impacted products: Unix (platform)
– Severity: 2/4
– Creation date: 22/04/2014
DESCRIPTION OF THE VULNERABILITY
The Xen product can be installed on an ARM processor.
However, several hardware features (cache control, coprocessors,
debug registers, processor specific registers) are not protected.
An attacker, who is located in a guest system, can therefore use
vulnerabilities in the ARM implementation of Xen, in order to
trigger a denial of service, and possibly to execute code.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
http://vigilance.fr/vulnerability/Xen-hardware-access-on-ARM-14628