CVE Vulnerabilities

CVE-2013-1920

Published: Apr 12, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:A/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running under memory pressure and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain event channel tracking table, which causes a use-after-free and allows local guest kernels to inject arbitrary events and gain privileges via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
XenXen3.0.2 (including)3.0.2 (including)
XenXen3.0.3 (including)3.0.3 (including)
XenXen3.0.4 (including)3.0.4 (including)
XenXen3.1.3 (including)3.1.3 (including)
XenXen3.1.4 (including)3.1.4 (including)
XenXen3.2.0 (including)3.2.0 (including)
XenXen3.2.1 (including)3.2.1 (including)
XenXen3.2.2 (including)3.2.2 (including)
XenXen3.2.3 (including)3.2.3 (including)
XenXen3.3.0 (including)3.3.0 (including)
XenXen3.3.1 (including)3.3.1 (including)
XenXen3.3.2 (including)3.3.2 (including)
XenXen3.4.0 (including)3.4.0 (including)
XenXen3.4.1 (including)3.4.1 (including)
XenXen3.4.2 (including)3.4.2 (including)
XenXen3.4.3 (including)3.4.3 (including)
XenXen3.4.4 (including)3.4.4 (including)
XenXen4.0.0 (including)4.0.0 (including)
XenXen4.0.1 (including)4.0.1 (including)
XenXen4.0.2 (including)4.0.2 (including)
XenXen4.0.3 (including)4.0.3 (including)
XenXen4.0.4 (including)4.0.4 (including)
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenUbuntuupstream*
Xen-3.1Ubuntuhardy*
Xen-3.2Ubuntuhardy*
Xen-3.2Ubuntuupstream*
Xen-3.3Ubuntuupstream*

References