The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of service (assertion failure) within pci core. This is fixed in 1.2. 6199e653418e is a mitigation for pre-1.1 versions, whereas 2b3dedfb9ba1 is a mitigation for 1.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-13T19:12:37

Updated: 2024-08-05T02:02:39.653Z

Reserved: 2019-11-09T00:00:00

Link: CVE-2019-18844

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-13T20:15:11.020

Modified: 2024-11-21T04:33:41.810

Link: CVE-2019-18844

cve-icon Redhat

No data.