PT-2013-6017 · Intel+1 · Xen+1
Kurt Seifried
·
Published
2013-11-23
·
Updated
2018-10-30
·
CVE-2013-6375
CVSS v2.0
7.9
High
| Vector | AV:A/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.2.x through 4.3.x
Description
The issue is related to Intel VT-d for PCI passthrough, where the TLB is not properly flushed after clearing a present translation table entry. This allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter".
Recommendations
For Xen versions 4.2.x through 4.3.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen