CVE-2013-1432: High severity XEN Xen vulnerability
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1432?
CVE-2013-1432 has a CVSS score indicating a high severity due to potential for denial of service and privilege escalation.
How do I fix CVE-2013-1432?
Fix CVE-2013-1432 by upgrading to a patched version of Xen that addresses the vulnerability.
Which versions of Xen are affected by CVE-2013-1432?
Xen versions 4.1.0 to 4.2.2 are affected by CVE-2013-1432.
What types of attacks can CVE-2013-1432 cause?
CVE-2013-1432 can lead to denial of service or possible privilege escalation for local PV guest kernels.
Who is at risk due to CVE-2013-1432?
Local users running PV guest kernels on affected Xen versions are at risk due to CVE-2013-1432.