First published: Sat Nov 23 2013(Updated: )
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.2.1 | |
Xen xen-unstable | =4.2.2 | |
Xen xen-unstable | =4.2.3 | |
Xen xen-unstable | =4.3.0 | |
Xen xen-unstable | =4.3.1 | |
openSUSE | =13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6375 is classified as a high severity vulnerability due to the potential for local guest administrators to cause a denial of service or escalate privileges.
To fix CVE-2013-6375, upgrade to a non-vulnerable version of Xen, such as versions 4.2.4 or 4.3.2 and later.
CVE-2013-6375 affects Xen versions 4.2.1, 4.2.2, 4.2.3, 4.3.0, and 4.3.1.
CVE-2013-6375 enables local guest administrators to potentially cause a denial of service or escalate privileges within the affected system.
There is no specific workaround for CVE-2013-6375; therefore, the best mitigation is to upgrade to a patched version.