PT-2010-5010 · Xen+1 · Xen+1

Publicado

2010-12-08

·

Atualizado

2018-10-10

·

CVE-2010-3699

CVSS v2.0

2.7

Baixa

VetorAV:A/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 3.x
Description The issue allows guest OS users to cause a denial of service via a kernel thread leak. This leak can prevent the device and guest OS from being shut down, create a zombie domain, cause a hang in zenwatch, or prevent unspecified xm commands from working properly. It is related to the netback, blkback, or blktap components.
Recommendations For Xen version 3.x, consider applying a patch to fix the kernel thread leak issue in the netback, blkback, or blktap components to prevent denial of service attacks. As a temporary workaround, consider restricting access to the affected components to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3699
DSA-2153-1
RHSA-2011:0004
RHSA-2011_0004

Produtos afetados

Red Hat
Xen