CVE-2013-0216
published 2013-02-18CVE-2013-0216: The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
PriorityP418medium5.2CVSS 2.0
AVAACMAuSCNINAC
EPSS
0.99%
59.2th percentile
The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
Affected
145 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.39-1 (bookworm) | linux 3.2.39-1 (bookworm) |
| linux | linux_kernel | <= 3.7.8 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.05.2MEDIUMAV:A/AC:M/Au:S/C:N/I:N/A:C
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
vendor_ubuntu5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g3g7-52m9-p44q: The Xen netback functionality in the Linux kernel before 3
ghsa_unreviewed·2022-05-05
CVE-2013-0216 [MEDIUM] CWE-20 GHSA-g3g7-52m9-p44q: The Xen netback functionality in the Linux kernel before 3
The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
OSV
CVE-2013-0216: The Xen netback functionality in the Linux kernel before 3
osv·2013-02-18·CVSS 5.2
CVE-2013-0216 [MEDIUM] CVE-2013-0216: The Xen netback functionality in the Linux kernel before 3
The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
Kernel
Merge branch 'netback'
kernel_security·2013-02-07·CVSS 5.2
CVE-2013-0216 [MEDIUM] Merge branch 'netback'
Merge branch 'netback'
Ian Campbell says:
The Xen netback implementation contains a couple of flaws which can
allow a guest to cause a DoS in the backend domain, potentially
affecting other domains in the system.
CVE-2013-0216 is a failure to sanity check the ring producer/consumer
pointers which can allow a guest to cause netback to loop for an
extended period preventing other work from occurring.
CVE-2013-0217 is a memory leak on an error path which is guest
triggerable.
The following series contains the fixes for these issues, as previously
included in Xen Security Advisory 39:
http://lists.xen.org/archives/html/xen-announce/2013-02/msg00001.html
Changes in v2:
- Typo and block comment format fixes
- Added stable Cc
Signed-off-by: David S. Miller
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-03-21·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driver. If
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI
d
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-03-12·CVSS 5.2
CVE-2013-0216 [MEDIUM] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS priv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-06·CVSS 5.2
CVE-2013-0216 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-02
Red Hat
kernel: xen: Linux netback DoS via malicious guest ring.
vendor_redhat·2013-02-05·CVSS 5.2
CVE-2013-0216 [MEDIUM] kernel: xen: Linux netback DoS via malicious guest ring.
kernel: xen: Linux netback DoS via malicious guest ring.
The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
Statement: This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-0216: linux - The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS u...
vendor_debian·2013·CVSS 5.2
CVE-2013-0216 [MEDIUM] CVE-2013-0216: linux - The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS u...
The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.
Scope: local
bookworm: resolved (fixed in 3.2.39-1)
bullseye: resolved (fixed in 3.2.39-1)
forky: resolved (fixed in 3.2.39-1)
sid: resolved (fixed in 3.2.39-1)
trixie: resolved (fixed in 3.2.39-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0216 CVE-2013-0217 kernel: xen: Linux netback DoS via malicious guest ring.
bugzilla·2013-02-13·CVSS 5.2
CVE-2013-0216 [MEDIUM] CVE-2013-0216 CVE-2013-0217 kernel: xen: Linux netback DoS via malicious guest ring.
CVE-2013-0216 CVE-2013-0217 kernel: xen: Linux netback DoS via malicious guest ring.
The Xen netback implementation contains a couple of flaws which can allow a guest to cause a DoS in the backend domain, potentially affecting other domains in the system.
CVE-2013-0216 is a failure to sanity check the ring producer/consumer pointers which can allow a guest to cause netback to loop for an extended period preventing other work from occurring.
CVE-2013-0217 is a memory leak on an error path which is guest triggerable.
A malicious guest with access to PV network devices can mount a DoS affecting the entire system.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 9108
Bugzilla
CVE-2013-0216 kernel: xen: Linux netback DoS via malicious guest ring. [fedora-all]
bugzilla·2013-02-13·CVSS 5.2
CVE-2013-0216 [MEDIUM] CVE-2013-0216 kernel: xen: Linux netback DoS via malicious guest ring. [fedora-all]
CVE-2013-0216 kernel: xen: Linux netback DoS via malicious guest ring. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this iss
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=48856286b64e4b66ec62b94e504d0b29c1ade664http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/02/05/12https://bugzilla.redhat.com/show_bug.cgi?id=910883https://github.com/torvalds/linux/commit/48856286b64e4b66ec62b94e504d0b29c1ade664http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=48856286b64e4b66ec62b94e504d0b29c1ade664http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/02/05/12https://bugzilla.redhat.com/show_bug.cgi?id=910883https://github.com/torvalds/linux/commit/48856286b64e4b66ec62b94e504d0b29c1ade664
2013-02-18
Published