Impact
A guest can trigger a BUG() in the Xen hypervisor when it is assigned a PCI device that has at least one Base Address Register on the I/O port space. The improper handling of HVM emulation return codes causes the hypervisor to panic, leading to a system-wide denial of service. The failure to validate the return status is a logic flaw that can be exploited by a guest with the appropriate PCI configuration.
Affected Systems
Xen hypervisor is affected. No specific version information is supplied, so any Xen installation that allows guests to own PCI devices with I/O BARs should be reviewed for the presence of this issue.
Risk and Exploitability
With a CVSS score of 8.8 and severity is high but the likelihood of exploitation remains low. The entry is not listed in CISA KEV, indicating no known active exploitation yet. The likely attack vector is that a guest owning a PCI device with an I/O BAR must be able to make an HVM call; the attack is thus internal to the hypervisor environment and does not require an external network connection. Exploitation conditions therefore involve the configuration of the guest and the hypervisor's PCI mapping. The bug can be triggered by generating a specific HVM state transition that relies on the incorrect handling of the return a loss of service for all guests on that host.
OpenCVE Enrichment