CVE-2013-4371: Use After Free
Use-after-free vulnerability in the libxllistcpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4371?
CVE-2013-4371 is classified as a denial of service vulnerability due to heap corruption and crash.
How do I fix CVE-2013-4371?
To fix CVE-2013-4371, upgrade to Xen versions 4.4.0 or later, which includes patches for this vulnerability.
Who is affected by CVE-2013-4371?
Users running Xen versions 4.2.x and 4.3.x are affected by CVE-2013-4371.
What causes CVE-2013-4371?
CVE-2013-4371 is caused by a use-after-free issue in the libxl_list_cpupool function when realloc fails under memory pressure.
What impact does CVE-2013-4371 have?
CVE-2013-4371 can lead to a denial of service, causing systems to crash and become unstable.