First published: Wed Aug 14 2013(Updated: )
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.0.2 | |
Xen xen-unstable | =4.0.3 | |
Xen xen-unstable | =4.0.4 | |
Xen xen-unstable | =4.1.0 | |
Xen xen-unstable | =4.1.1 | |
Xen xen-unstable | =4.1.2 | |
Xen xen-unstable | =4.1.3 | |
Xen xen-unstable | =4.1.4 | |
Xen xen-unstable | =4.1.5 | |
Xen xen-unstable | =4.2.0 | |
Xen xen-unstable | =4.2.1 | |
Xen xen-unstable | =4.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2078 has a medium severity rating as it allows local users to cause a denial of service through a hypervisor crash.
To fix CVE-2013-2078, upgrade to Xen version 4.3.x or later, which addresses this vulnerability.
CVE-2013-2078 affects Xen versions 4.0.2 through 4.0.4, all 4.1.x versions, and 4.2.x versions.
CVE-2013-2078 facilitates a denial of service attack against the hypervisor via specific XSETBV instruction bit combinations.
CVE-2013-2078 cannot be exploited remotely as it requires local access by PV guest users.