CVE Vulnerabilities

CVE-2010-4255

Published: Jan 25, 2011 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.1 MEDIUM
AV:A/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
6.1 MODERATE
AV:A/AC:L/Au:N/C:N/I:N/A:C
RedHat/V3
Ubuntu
LOW

The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.

Affected Software

Name Vendor Start Version End Version
Xen Citrix * 4.0.1 (including)
Xen Citrix 3.0.2 (including) 3.0.2 (including)
Xen Citrix 3.0.3 (including) 3.0.3 (including)
Xen Citrix 3.0.4 (including) 3.0.4 (including)
Xen Citrix 3.1.2 (including) 3.1.2 (including)
Xen Citrix 3.1.3 (including) 3.1.3 (including)
Xen Citrix 3.1.4 (including) 3.1.4 (including)
Xen Citrix 3.2.0 (including) 3.2.0 (including)
Xen Citrix 3.2.1 (including) 3.2.1 (including)
Xen Citrix 3.2.2 (including) 3.2.2 (including)
Xen Citrix 3.2.3 (including) 3.2.3 (including)
Xen Citrix 3.3.0 (including) 3.3.0 (including)
Xen Citrix 3.3.1 (including) 3.3.1 (including)
Xen Citrix 3.3.2 (including) 3.3.2 (including)
Xen Citrix 3.4.0 (including) 3.4.0 (including)
Xen Citrix 3.4.1 (including) 3.4.1 (including)
Xen Citrix 3.4.2 (including) 3.4.2 (including)
Xen Citrix 3.4.3 (including) 3.4.3 (including)
Xen Citrix 4.0.0 (including) 4.0.0 (including)
Red Hat Enterprise Linux 5 RedHat kernel-0:2.6.18-238.el5 *
Xen Ubuntu dapper *
Xen Ubuntu upstream *
Xen-3.1 Ubuntu hardy *
Xen-3.2 Ubuntu hardy *
Xen-3.3 Ubuntu karmic *
Xen-3.3 Ubuntu lucid *
Xen-3.3 Ubuntu maverick *
Xen-3.3 Ubuntu natty *

References