PT-2013-2134 · Xen · Xen

Publicado

2013-03-07

·

Atualizado

2024-06-15

·

CVE-2013-0151

CVSS v2.0

4.6

Média

VetorAV:A/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen version 4.2.x
Description The issue allows guest OS users to cause a denial of service by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs, resulting in long-duration page mappings and host OS crash. This is due to the do hvm op function not preventing HVM PARAM NESTEDHVM operations.
Recommendations For Xen version 4.2.x, consider restricting administrative access to HVM guests or limiting the number of VCPUs in a domain to minimize the risk of exploitation. As a temporary workaround, consider disabling the do hvm op function or restricting HVM PARAM NESTEDHVM operations until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0151
OPENSUSE-SU-2024:10196-1

Produtos afetados

Xen