CVE-2013-4494: Input Validation
Published Nov 2, 2013
·Updated
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the pagealloclock and granttable.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
Affected Software
4 affected components
XEN Xen>=4.1.0<=4.1.6.1
XEN Xen>=4.2.0<=4.2.5
XEN Xen>=4.3.0<=4.3.4
Debian Debian Linux=7.0
Event History
Nov 2, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What are the risks associated with CVE-2013-4494?
CVE-2013-4494 allows local guest administrators to create a denial of service situation resulting in host deadlock.
2
What versions of Xen are affected by CVE-2013-4494?
CVE-2013-4494 affects Xen versions prior to 4.1.x, 4.2.x, and 4.3.x.
3
How can I mitigate the issues caused by CVE-2013-4494?
To mitigate CVE-2013-4494, you should upgrade your Xen installation to a version beyond 4.3.4.
4
Who is at risk due to CVE-2013-4494?
Local guest administrators with access to multiple virtual CPUs are at risk due to CVE-2013-4494.
5
What type of vulnerability is CVE-2013-4494 classified as?
CVE-2013-4494 is classified as a denial of service vulnerability.