CVE-2013-4551: Input Validation
Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which allows local HVM guest users to cause a denial of service (host crash) via unspecified vectors related to "guest VMX instruction execution."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4551?
CVE-2013-4551 is classified as a medium severity vulnerability as it can lead to denial of service through host crash.
How do I fix CVE-2013-4551?
To fix CVE-2013-4551, you should upgrade to a patched version of Xen that addresses the vulnerability.
What versions of Xen are affected by CVE-2013-4551?
CVE-2013-4551 affects Xen versions 4.2.0 through 4.2.3 and 4.3.0 through 4.3.1.
What is the impact of CVE-2013-4551 on my system?
The impact of CVE-2013-4551 is a potential denial of service that could cause the host system to crash.
Is nested virtualization the cause of CVE-2013-4551?
CVE-2013-4551 occurs when nested virtualization is disabled, allowing local HVM guest users to exploit the vulnerability.