PT-2010-5010 · Xen+1 · Xen+1

Published

2010-12-08

·

Updated

2018-10-10

·

CVE-2010-3699

CVSS v2.0

2.7

Low

VectorAV:A/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 3.x
Description The issue allows guest OS users to cause a denial of service via a kernel thread leak. This leak can prevent the device and guest OS from being shut down, create a zombie domain, cause a hang in zenwatch, or prevent unspecified xm commands from working properly. It is related to the netback, blkback, or blktap components.
Recommendations For Xen version 3.x, consider applying a patch to fix the kernel thread leak issue in the netback, blkback, or blktap components to prevent denial of service attacks. As a temporary workaround, consider restricting access to the affected components to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3699
DSA-2153-1
RHSA-2011:0004
RHSA-2011_0004

Affected Products

Red Hat
Xen