CVE Vulnerabilities

CVE-2013-1432

Published: Aug 28, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.4 HIGH
AV:A/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
6.5 IMPORTANT
AV:A/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenXen4.2.2 (including)4.2.2 (including)
XenUbuntuprecise*
XenUbuntuquantal*
XenUbunturaring*
XenUbuntuupstream*
Xen-3.3Ubuntulucid*
Xen-3.3Ubuntuupstream*

References