PT-2010-5010 · Xen+1 · Xen+1
Published
2010-12-08
·
Updated
2018-10-10
·
CVE-2010-3699
CVSS v2.0
2.7
Low
| Vector | AV:A/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.x
Description
The issue allows guest OS users to cause a denial of service via a kernel thread leak. This leak can prevent the device and guest OS from being shut down, create a zombie domain, cause a hang in zenwatch, or prevent unspecified xm commands from working properly. It is related to the netback, blkback, or blktap components.
Recommendations
For Xen version 3.x, consider applying a patch to fix the kernel thread leak issue in the netback, blkback, or blktap components to prevent denial of service attacks. As a temporary workaround, consider restricting access to the affected components to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Xen