PT-2013-3467 · Xen+1 · Xen+1

Publicado

2013-05-13

·

Atualizado

2024-06-15

·

CVE-2013-1917

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 3.1 through 4.x
Description The issue allows PV guest users to cause a denial of service by triggering a #GP fault, which is not properly handled, leading to a hypervisor crash. This occurs when running 64-bit hosts on Intel CPUs and using an IRET after a SYSENTER instruction without clearing the NT flag.
Recommendations For Xen versions 3.1 through 4.x, consider applying a patch that properly handles #GP faults and clears the NT flag when using an IRET after a SYSENTER instruction to prevent hypervisor crashes.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1917
DSA-2662-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2013_1075-1

Produtos afetados

Suse
Xen