CVE-2013-0241: Low severity xf86-video-qxl vulnerability
A flaw was found in the way spice connection breakups were handled in the qemu-kvm qxl driver. Some of the qxl port i/o commands were waiting for the spice server to complete the actions, while the corresponding thread holds qemumutex mutex, potentially blocking other threads in the guest's qemu-kvm process. An user able to initiate spice connection to the guest could use this flaw to make guest temporarily unavailable or, in case kernel.softlockuppanic in the guest was set, crash the guest.
Upstream fixes: xf86-video-qxl commit http://cgit.freedesktop.org/xorg/driver/xf86-video-qxl/commit/?id=30b4b72cdbdf9f0e92a8d1c4e01779f60f15a741
which relies on qemu-kvm functionality introduced by commit http://git.kernel.org/?p=virt/kvm/qemu-kvm.git;a=commit;h=5ff4e36c
Other sources
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemumutex mutex. NOTE: some of these details are obtained from third party information.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0241?
CVE-2013-0241 has a medium severity rating due to potential denial of service risks in affected systems.
How do I fix CVE-2013-0241?
To fix CVE-2013-0241, upgrade to the latest version of the qxl driver or apply the relevant patches provided by your distribution.
Which software is affected by CVE-2013-0241?
CVE-2013-0241 affects various versions of the qxl graphics driver and specific versions of Ubuntu and Red Hat Linux distributions.
What are the potential impacts of CVE-2013-0241?
The potential impacts of CVE-2013-0241 include performance degradation and service interruption in virtualized environments.
Is CVE-2013-0241 still a threat?
CVE-2013-0241 could still pose a threat if vulnerable systems remain unpatched, particularly in environments using affected versions.