CVE-2013-4329: Medium severity xen xapi vulnerability
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4329?
CVE-2013-4329 is considered a high severity vulnerability due to its potential to allow privilege escalation or denial of service.
How do I fix CVE-2013-4329?
To mitigate CVE-2013-4329, it is recommended to upgrade to a patched version of Xen that addresses this vulnerability.
What systems are affected by CVE-2013-4329?
CVE-2013-4329 affects Xen versions 4.0.x to 4.2.x when IOMMU is disabled.
What is the impact of exploiting CVE-2013-4329?
Exploitation of CVE-2013-4329 can allow local HVM guest domains to perform unauthorized actions and potentially crash the host.
Is there a workaround for CVE-2013-4329?
Disabling PCI passthrough for affected devices until a patch can be applied is a potential workaround for CVE-2013-4329.