Back to search
CVE-2020-15687
Published: Aug 31, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This attack results in a corrupt state and Denial of Service (DoS) for previously assigned PCIe devices to the Service VM at runtime.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://projectacrn.github.io/latest/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now