CVE-2010-4247Improper Input Validation in Citrix XEN

Severity
5.5MEDIUMNVD
EPSS
0.6%
top 30.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateMay 14

Description

The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:A/AC:L/C:N/I:N/A:CExploitability: 5.1 | Impact: 6.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-9hwc-j324-r98v: The do_block_io_op function in (1) drivers/xen/blkback/blkback2022-05-14

📋Vendor Advisories

3
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp2011-10-12
Ubuntu
Linux kernel vulnerabilities2011-07-15
Red Hat
xen: request-processing loop is unbounded in blkback2008-01-18

💬Community

1
Bugzilla
CVE-2010-4247 xen: request-processing loop is unbounded in blkback2010-11-23