CVE-2013-1918: Buffer Overflow
Published May 13, 2013
·Updated
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
Affected Software
9 affected components
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
Event History
May 13, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1918?
CVE-2013-1918 has a medium severity rating due to its potential for creating a denial of service vulnerability.
2
How do I fix CVE-2013-1918?
To fix CVE-2013-1918, you should upgrade to a later version of Xen that has addressed this vulnerability.
3
Which versions of Xen are affected by CVE-2013-1918?
CVE-2013-1918 affects Xen versions 4.1.x and 4.2.x, including all specific patches up to those versions.
4
Can CVE-2013-1918 be exploited remotely?
No, CVE-2013-1918 can only be exploited locally by privileged PV kernels.
5
What type of vulnerability is CVE-2013-1918?
CVE-2013-1918 is a denial of service vulnerability caused by non-preemptible page table manipulation operations.