Skip to main content

Table 5 Hypercall-based attacks by HInjector

From: Hardware assisted hypervisor introspection

Attacks

Hypercalls

Repeats

Args

CVE-2012-3495

physdev_op

100

cmd=23(physdev_get_free_pirq

->type=1)

CVE-2012-5513

memory_op

1

cmd=11(xen_mem_exchange{in{

nr_extents=1, extend_order=0,

extent_start=1, domid=2},

out{nr_extents=16, extend_order=1,

extend_start=1844660388597701000,

domid=2})

CVE-2012-5510

grant_table_op

100*2

cmd=8(gnttab_set_version

->version=1/2)

example1

grant_table_op

100*2

cmd=8(gnttab_set_version

->version=1/2)

example2

get_debugreg

2

reg=1,3,4

example3

get_debugreg set_trap_table

2+1

reg=1,3,4 trap_info{flags=10,

cs=2,address=3}

default

grant_table_op

100*2

cmd=8(gnttab_set_version

->version=1/2)