CVE-2011-1166
published 2014-01-07CVE-2011-1166: Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode…
PriorityP415medium5.5CVSS 2.0
AVAACLAuSCNINAC
EPSS
0.67%
47.7th percentile
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.0-1 (bookworm) | xen 4.1.0-1 (bookworm) |
| xen | xen | <= 4.0.1 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.0-1 | 4.1.0-1 |
| xen | xen | >= 0 < 4.1.0-1 | 4.1.0-1 |
| xen | xen | >= 0 < 4.1.0-1 | 4.1.0-1 |
| xen | xen | >= 0 < 4.1.0-1 | 4.1.0-1 |
CVSS provenance
nvdv2.05.5MEDIUMAV:A/AC:L/Au:S/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cr7m-pjw9-g2r9: Xen, possibly before 4
ghsa_unreviewed·2022-05-17
CVE-2011-1166 [MEDIUM] CWE-20 GHSA-cr7m-pjw9-g2r9: Xen, possibly before 4
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
OSV
CVE-2011-1166: Xen, possibly before 4
osv·2014-01-07·CVSS 5.5
CVE-2011-1166 [MEDIUM] CVE-2011-1166: Xen, possibly before 4
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
Red Hat
kernel: xen: x86_64: fix error checking in arch_set_info_guest()
vendor_redhat·2011-03-14·CVSS 5.5
CVE-2011-1166 [MEDIUM] kernel: xen: x86_64: fix error checking in arch_set_info_guest()
kernel: xen: x86_64: fix error checking in arch_set_info_guest()
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
Debian
CVE-2011-1166: xen - Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of s...
vendor_debian·2011·CVSS 5.5
CVE-2011-1166 [MEDIUM] CVE-2011-1166: xen - Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of s...
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
Scope: local
bookworm: resolved (fixed in 4.1.0-1)
bullseye: resolved (fixed in 4.1.0-1)
forky: resolved (fixed in 4.1.0-1)
sid: resolved (fixed in 4.1.0-1)
trixie: resolved (fixed in 4.1.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2378 Mozilla: Dangling pointer vulnerability in appendChild
bugzilla·2011-08-14·CVSS 10.0
CVE-2011-2378 [CRITICAL] CVE-2011-2378 Mozilla: Dangling pointer vulnerability in appendChild
CVE-2011-2378 Mozilla: Dangling pointer vulnerability in appendChild
Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that appendChild did not correctly account for DOM objects it operated upon and could be exploited to dereference an invalid pointer.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-30.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:1166 https://rhn.redhat.com/errata/RHSA-2011-1166.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:1164 https://rhn.redhat.com/errata/RHSA-2011-1164.html
Bugzilla
CVE-2011-0084 Mozilla: Crash in SVGTextElement.getCharNumAtPosition()
bugzilla·2011-08-14·CVSS 10.0
CVE-2011-0084 [CRITICAL] CVE-2011-0084 Mozilla: Crash in SVGTextElement.getCharNumAtPosition()
CVE-2011-0084 Mozilla: Crash in SVGTextElement.getCharNumAtPosition()
Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that a SVG text manipulation routine contained a dangling pointer vulnerability.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-30.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:1166 https://rhn.redhat.com/errata/RHSA-2011-1166.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:1164 https://rhn.redhat.com/errata/RHSA-2011-1164.html
Bugzilla
CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()
bugzilla·2011-03-17·CVSS 5.5
CVE-2011-1166 [MEDIUM] CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()
CVE-2011-1166 kernel: xen: x86_64: fix error checking in arch_set_info_guest()
Cannot specify user mode execution without specifying user-mode pagetables.
The problem is that a 64-bit guest can get one of its vcpus into non-kernel mode without first providing a valid non-kernel pagetable. The iret-into-userspace path has the right checks, but just setting the context on a fresh vcpu doesn't. :( The observed failure mode is usually a hard lockup of the host. This affects 64-bit version of kernel-xen.
Upstream commit:
http://xenbits.xen.org/hg/staging/xen-unstable.hg/rev/c79aae866ad8
Reference:
https://bugzilla.novell.com/show_bug.cgi?id=679344
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2011:0833 https://rhn.redhat.com/errata/
http://downloads.avaya.com/css/P8/documents/100145416http://rhn.redhat.com/errata/RHSA-2011-0833.htmlhttp://wiki.xen.org/wiki/Security_Announcements#XSA-1_Host_crash_due_to_failure_to_correctly_validate_PV_kernel_execution_state.http://downloads.avaya.com/css/P8/documents/100145416http://rhn.redhat.com/errata/RHSA-2011-0833.htmlhttp://wiki.xen.org/wiki/Security_Announcements#XSA-1_Host_crash_due_to_failure_to_correctly_validate_PV_kernel_execution_state.
2014-01-07
Published