PT-2013-3134 · Xen+1 · Xen+1

Andrew Cooper

·

Published

2013-07-01

·

Updated

2017-06-30

·

CVE-2013-1432

CVSS v2.0

7.4

High

VectorAV:A/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 4.1.x through 4.2.x
Description The issue is related to the improper maintenance of references on pages stored for deferred cleanup. This can be exploited by local PV guest kernels to cause a denial of service, resulting in a premature page free and hypervisor crash, or possibly gain privileges via unspecified vectors.
Recommendations For Xen versions 4.1.x through 4.2.x, consider applying the necessary patches to fix the issue, specifically ensuring that the XSA-45 patch is properly applied and the deferred cleanup mechanism is corrected to prevent premature page freeing and potential privilege escalation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1432
DSA-3006-1
MGASA-2013-0197
SUSE-SU-2013_1735-1
SUSE-SU-2013_1774-1

Affected Products

Suse
Xen