PT-2013-3467 · Xen+1 · Xen+1
Published
2013-05-13
·
Updated
2024-06-15
·
CVE-2013-1917
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.1 through 4.x
Description
The issue allows PV guest users to cause a denial of service by triggering a #GP fault, which is not properly handled, leading to a hypervisor crash. This occurs when running 64-bit hosts on Intel CPUs and using an IRET after a SYSENTER instruction without clearing the NT flag.
Recommendations
For Xen versions 3.1 through 4.x, consider applying a patch that properly handles #GP faults and clears the NT flag when using an IRET after a SYSENTER instruction to prevent hypervisor crashes.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen