CVE Reference: CVE-2013-0151

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2013-0151

Description:
The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA55082

MLIST
  http://openwall.com/lists/oss-security/2013/01/22/10

GENTOO
  http://security.gentoo.org/glsa/glsa-201309-24.xml

CONFIRM
  http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=d60d7082289a74e44b3dc8f67df46c3404ca08bf


Return to the previous page.