CVE Vulnerabilities

CVE-2013-4554

Published: Dec 24, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.2 MEDIUM
AV:A/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6 MODERATE
AV:L/AC:H/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.

Affected Software

NameVendorStart VersionEnd Version
XenXen3.0.3 (including)3.0.3 (including)
XenXen3.0.4 (including)3.0.4 (including)
XenXen3.1.3 (including)3.1.3 (including)
XenXen3.1.4 (including)3.1.4 (including)
XenXen3.2.0 (including)3.2.0 (including)
XenXen3.2.1 (including)3.2.1 (including)
XenXen3.2.2 (including)3.2.2 (including)
XenXen3.2.3 (including)3.2.3 (including)
XenXen3.3.0 (including)3.3.0 (including)
XenXen3.3.1 (including)3.3.1 (including)
XenXen3.3.2 (including)3.3.2 (including)
XenXen3.4.0 (including)3.4.0 (including)
XenXen3.4.1 (including)3.4.1 (including)
XenXen3.4.2 (including)3.4.2 (including)
XenXen3.4.3 (including)3.4.3 (including)
XenXen3.4.4 (including)3.4.4 (including)
XenXen4.0.0 (including)4.0.0 (including)
XenXen4.0.1 (including)4.0.1 (including)
XenXen4.0.2 (including)4.0.2 (including)
XenXen4.0.3 (including)4.0.3 (including)
XenXen4.0.4 (including)4.0.4 (including)
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.1.5 (including)4.1.5 (including)
XenXen4.1.6.1 (including)4.1.6.1 (including)
Red Hat Enterprise Linux 5RedHatkernel-0:2.6.18-371.6.1.el5*
XenUbuntudevel*
XenUbuntuprecise*
XenUbuntuquantal*
XenUbunturaring*
XenUbuntusaucy*
Xen-3.3Ubuntulucid*
Xen-3.3Ubuntuupstream*

References