CVE Vulnerabilities

CVE-2013-4329

Published: Sep 12, 2013 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:A/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
6.5 IMPORTANT
AV:A/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.

Affected Software

Name Vendor Start Version End Version
Xen Xen 4.0.0 (including) 4.0.0 (including)
Xen Xen 4.0.1 (including) 4.0.1 (including)
Xen Xen 4.0.2 (including) 4.0.2 (including)
Xen Xen 4.0.3 (including) 4.0.3 (including)
Xen Xen 4.0.4 (including) 4.0.4 (including)
Xen Xen 4.1.0 (including) 4.1.0 (including)
Xen Xen 4.1.1 (including) 4.1.1 (including)
Xen Xen 4.1.2 (including) 4.1.2 (including)
Xen Xen 4.1.3 (including) 4.1.3 (including)
Xen Xen 4.1.4 (including) 4.1.4 (including)
Xen Xen 4.1.5 (including) 4.1.5 (including)
Xen Xen 4.2.0 (including) 4.2.0 (including)
Xen Xen 4.2.1 (including) 4.2.1 (including)
Xen Xen 4.2.2 (including) 4.2.2 (including)
Xen Xen 4.2.3 (including) 4.2.3 (including)
Xen Ubuntu precise *
Xen Ubuntu quantal *
Xen Ubuntu raring *
Xen-3.3 Ubuntu lucid *
Xen-3.3 Ubuntu upstream *

References