CVE-2010-4247: Input Validation

Published Nov 23, 2010
·
Updated

If the frontend pass a bad index of production request, the backend will enter an endless loop and then cause a excessive CPU consumption.

This issue has been fixed in upstream by: changeset: 391:77f831cbb91d user: Keir Fraser <keir.fraser> date: Fri Jan 18 16:52:25 2008 +0000 summary: blkback: Request-processing loop is unbounded and hence requires a http://xenbits.xensource.com/linux-2.6.18-xen.hg?rev/77f831cbb91d

changeset: 392:7070d34f251c user: Keir Fraser <keir.fraser> date: Mon Jan 21 11:43:31 2008 +0000 summary: blkback/blktap: Check for kthreadshouldstop() in inner loop, http://xenbits.xensource.com/linux-2.6.18-xen.hg?rev/7070d34f251c

Version-Release number of selected component (if applicable): 2.6.18-194.el5xen

How reproducible:

Steps to Reproduce: 1. build a guest kernel with the patch attached. 2. run domU with the patched kernel

Actual results: Dom0 got hung.

Expected results: Dom0 shouldn't be impacted by a bad guest.

Other sources

The doblockioop function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.

Debian

Affected Software

27 affected components
debian/linux-2.6
Citrix Xen<=3.3.2
Citrix Xen=3.0.2
Citrix Xen=3.0.3
Citrix Xen=3.0.4
Citrix Xen=3.1.3
Citrix Xen=3.1.4
Citrix Xen=3.2.0
Citrix Xen=3.2.1
Citrix Xen=3.2.2
Citrix Xen=3.2.3
Citrix Xen=3.3.0
Citrix Xen=3.3.1
Linux Linux kernel=2.6.18
All of the following
Any of the following
Citrix Xen<=3.3.2
Citrix Xen=3.0.2
Citrix Xen=3.0.3
Citrix Xen=3.0.4
Citrix Xen=3.1.3
Citrix Xen=3.1.4
Citrix Xen=3.2.0
Citrix Xen=3.2.1
Citrix Xen=3.2.2
Citrix Xen=3.2.3
Citrix Xen=3.3.0
Citrix Xen=3.3.1
Linux Linux kernel=2.6.18

Event History

Nov 23, 2010
Data Sourced
via Red Hat·08:32 AM
DescriptionSeverityAffected Software
Jan 11, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
03:00 AM
DescriptionWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·09:54 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:39 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2010-4247?

CVE-2010-4247 has been assessed with moderate severity due to its potential for excessive CPU consumption.

2

How do I fix CVE-2010-4247?

Fix CVE-2010-4247 by updating to the latest version of XenServer that includes the patch from changeset 391:77f831cbb91d.

3

Which versions of XenServer are affected by CVE-2010-4247?

CVE-2010-4247 affects XenServer versions up to 3.3.2, including specific versions 3.0.2 to 3.3.1.

4

What causes the issue in CVE-2010-4247?

CVE-2010-4247 is caused by the frontend passing a bad index of production request, resulting in an endless loop.

5

Is CVE-2010-4247 present in Linux kernel version 2.6.18?

No, the vulnerability CVE-2010-4247 does not affect Linux kernel version 2.6.18.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203