CVE-2013-2212: Buffer Overflow
Published Aug 28, 2013
·Updated
The vmxsetucmode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.
Affected Software
23 affected components
XEN Xen=3.3.0
XEN Xen=3.3.1
XEN Xen=3.3.2
XEN Xen=3.4.0
XEN Xen=3.4.1
XEN Xen=3.4.2
XEN Xen=3.4.3
XEN Xen=3.4.4
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.3.0
Event History
Aug 28, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2212?
CVE-2013-2212 has a medium severity rating due to its potential to cause denial of service attacks on hypervisors.
2
How do I fix CVE-2013-2212?
To mitigate CVE-2013-2212, upgrade to a fixed version of Xen that addresses this vulnerability.
3
Which versions of Xen are affected by CVE-2013-2212?
CVE-2013-2212 affects Xen versions 3.3.0 through 4.3.0.
4
What types of attacks can CVE-2013-2212 lead to?
CVE-2013-2212 can be exploited to lead to CPU consumption and potentially cause hypervisor or guest kernel panics.
5
Who can exploit CVE-2013-2212?
Local HVM guests with access to memory mapped I/O regions can potentially exploit CVE-2013-2212.