CVE-2013-0190
published 2013-02-13CVE-2013-0190: The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.37%
29.5th percentile
The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.39-1 (bookworm) | linux 3.2.39-1 (bookworm) |
| linux | linux_kernel | <= 2.6.23 | — |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
| linux | linux_kernel | >= 0 < 3.2.39-1 | 3.2.39-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-03-21·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driver. If
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI
d
Ubuntu
Linux kernel (EC2) vulnerability
vendor_ubuntu·2013-02-19
CVE-2013-0190 Linux kernel (EC2) vulnerability
Title: Linux kernel (EC2) vulnerability
Summary: The system could be made to crash under certain conditions.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-02-14
CVE-2013-0190 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-02-12·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
Instructions: After a stand
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-02-12·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Florian Weimer discovered that hypervkvpd, which is distributed in the
Linux kernel, was not correctly validating source addresses of netlink
packets. An untrusted local user can cause a denial of service by causing
hypervkvpd to exit. (CVE-2012
Red Hat
kernel: stack corruption in xen_failsafe_callback()
vendor_redhat·2013-01-16·CVSS 4.9
CVE-2013-0190 [MEDIUM] kernel: stack corruption in xen_failsafe_callback()
kernel: stack corruption in xen_failsafe_callback()
The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.
Statement: This issue did not affect Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-0190: linux - The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other ...
vendor_debian·2013·CVSS 4.9
CVE-2013-0190 [MEDIUM] CVE-2013-0190: linux - The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other ...
The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.
Scope: local
bookworm: resolved (fixed in 3.2.39-1)
bullseye: resolved (fixed in 3.2.39-1)
forky: resolved (fixed in 3.2.39-1)
sid: resolved (fixed in 3.2.39-1)
trixie: resolved (fixed in 3.2.39-1)
GHSA
GHSA-94hw-6g8m-4wf2: The xen_failsafe_callback function in Xen for the Linux kernel 2
ghsa_unreviewed·2022-05-05
CVE-2013-0190 [MEDIUM] CWE-20 GHSA-94hw-6g8m-4wf2: The xen_failsafe_callback function in Xen for the Linux kernel 2
The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.
OSV
CVE-2013-0190: The xen_failsafe_callback function in Xen for the Linux kernel 2
osv·2013-02-13·CVSS 4.9
CVE-2013-0190 [MEDIUM] CVE-2013-0190: The xen_failsafe_callback function in Xen for the Linux kernel 2
The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.
Kernel
x86/xen: don't assume %ds is usable in xen_iret for 32-bit PVOPS.
kernel_security·2013-01-24·CVSS 4.9
CVE-2013-0190 [MEDIUM] x86/xen: don't assume %ds is usable in xen_iret for 32-bit PVOPS.
x86/xen: don't assume %ds is usable in xen_iret for 32-bit PVOPS.
This fixes CVE-2013-0228 / XSA-42
Drew Jones while working on CVE-2013-0190 found that that unprivileged guest user
in 32bit PV guest can use to crash the > guest with the panic like this:
general protection fault: 0000 [#1] SMP
last sysfs file: /sys/devices/vbd-51712/block/xvda/dev
Modules linked in: sunrpc ipt_REJECT nf_conntrack_ipv4 nf_defrag_ipv4
iptable_filter ip_tables ip6t_REJECT nf_conntrack_ipv6 nf_defrag_ipv6
xt_state nf_conntrack ip6table_filter ip6_tables ipv6 xen_netfront ext4
mbcache jbd2 xen_blkfront dm_mirror dm_region_hash dm_log dm_mod [last
unloaded: scsi_wait_scan]
Pid: 1250, comm: r Not tainted 2.6.32-356.el6.i686 #1
EIP: 0061:[] EFLAGS: 00010086 CPU: 0
EIP is at xen_iret+0x12/0x2b
EAX: eb8d0000 EBX
Kernel
Merge tag 'stable/for-linus-3.8-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen
kernel_security·2013-01-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Merge tag 'stable/for-linus-3.8-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen
Merge tag 'stable/for-linus-3.8-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen
Pull Xen fixes from Konrad Rzeszutek Wilk:
- CVE-2013-0190/XSA-40 (or stack corruption for 32-bit PV kernels)
- Fix racy vma access spotted by Al Viro
- Fix mmap batch ioctl potentially resulting in large O(n) page allcations.
- Fix vcpu online/offline BUG:scheduling while atomic..
- Fix unbound buffer scanning for more than 32 vCPUs.
- Fix grant table being incorrectly initialized
- Fix incorrect check in pciback
- Allow privcmd in backend domains.
Fix up whitespace conflict due to ugly merge resolution in Xen tree in
arch/arm/xen/enlighten.c
* tag 'stable/for-linus-3.8-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen:
xen: Fix stack corruption in xen_failsafe_callba
Kernel
xen: Fix stack corruption in xen_failsafe_callback for 32bit PVOPS guests.
kernel_security·2013-01-16·CVSS 4.9
CVE-2013-0190 [MEDIUM] xen: Fix stack corruption in xen_failsafe_callback for 32bit PVOPS guests.
xen: Fix stack corruption in xen_failsafe_callback for 32bit PVOPS guests.
This fixes CVE-2013-0190 / XSA-40
There has been an error on the xen_failsafe_callback path for failed
iret, which causes the stack pointer to be wrong when entering the
iret_exc error path. This can result in the kernel crashing.
In the classic kernel case, the relevant code looked a little like:
popl %eax # Error code from hypervisor
jz 5f
addl $16,%esp
jmp iret_exc # Hypervisor said iret fault
5: addl $16,%esp
# Hypervisor said segment selector fault
Here, there are two identical addls on either option of a branch which
appears to have been optimised by hoisting it above the jz, and
converting it to an lea, which leaves the flags register unaffected.
In the PVOPS case, the code looks like:
popl_cfi %eax #
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0190 kernel: stack corruption in xen_failsafe_callback() [fedora-all]
bugzilla·2013-01-16·CVSS 4.9
CVE-2013-0190 [MEDIUM] CVE-2013-0190 kernel: stack corruption in xen_failsafe_callback() [fedora-all]
CVE-2013-0190 kernel: stack corruption in xen_failsafe_callback() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
Bugzilla
CVE-2013-0190 kernel: stack corruption in xen_failsafe_callback()
bugzilla·2013-01-16·CVSS 4.9
CVE-2013-0190 [MEDIUM] CVE-2013-0190 kernel: stack corruption in xen_failsafe_callback()
CVE-2013-0190 kernel: stack corruption in xen_failsafe_callback()
A flaw was found in the way xen_failsafe_callback() handled failed iret,
which causes the stack pointer to be wrong when entering the
iret_exc error path. An unprivileged local guest user in the 32-bit PV
Xen domain could use this flaw to crash the guest.
References:
http://www.openwall.com/lists/oss-security/2013/01/16/6
Acknowledgements:
Red Hat would like to thank the Andrew Cooper of Citrix for reporting this issue.
Discussion:
Created attachment 679616
Upstream proposed patch
---
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 896051]
---
Statement:
This issue did not affect Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
---
I'm brewing a build with the proposed patch:
https
http://rhn.redhat.com/errata/RHSA-2013-0496.htmlhttp://www.openwall.com/lists/oss-security/2013/01/16/6http://www.openwall.com/lists/oss-security/2013/01/16/8http://www.securityfocus.com/bid/57433http://www.ubuntu.com/usn/USN-1725-1http://www.ubuntu.com/usn/USN-1728-1https://bugzilla.redhat.com/show_bug.cgi?id=896038http://rhn.redhat.com/errata/RHSA-2013-0496.htmlhttp://www.openwall.com/lists/oss-security/2013/01/16/6http://www.openwall.com/lists/oss-security/2013/01/16/8http://www.securityfocus.com/bid/57433http://www.ubuntu.com/usn/USN-1725-1http://www.ubuntu.com/usn/USN-1728-1https://bugzilla.redhat.com/show_bug.cgi?id=896038
2013-02-13
Published