CVE-2013-0231
published 2013-02-13CVE-2013-0231: The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.44%
35.7th percentile
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-1 (bookworm) | linux 3.2.41-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-03-21·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driver. If
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driv
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
A flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI
d
Red Hat
kernel: xen: pciback DoS via not rate limited log messages
vendor_redhat·2013-02-05·CVSS 4.9
CVE-2013-0231 [MEDIUM] kernel: xen: pciback DoS via not rate limited log messages
kernel: xen: pciback DoS via not rate limited log messages
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
Statement: This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-0231: linux - The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/c...
vendor_debian·2013·CVSS 4.9
CVE-2013-0231 [MEDIUM] CVE-2013-0231: linux - The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/c...
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.2.41-1)
sid: resolved (fixed in 3.2.41-1)
trixie: resolved (fixed in 3.2.41-1)
GHSA
GHSA-p9q5-jhcx-489h: The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi
ghsa_unreviewed·2022-05-05
CVE-2013-0231 [MEDIUM] CWE-119 GHSA-p9q5-jhcx-489h: The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
OSV
CVE-2013-0231: The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi
osv·2013-02-13·CVSS 4.9
CVE-2013-0231 [MEDIUM] CVE-2013-0231: The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi
The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.
Kernel
Merge tag 'stable/for-linus-3.8-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen
kernel_security·2013-02-08·CVSS 4.9
CVE-2013-0231 [MEDIUM] Merge tag 'stable/for-linus-3.8-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen
Merge tag 'stable/for-linus-3.8-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen
Pull Xen fixes from Konrad Rzeszutek Wilk:
"This has two fixes. One is a security fix wherein we would spam the
kernel printk buffer if one of the guests was misbehaving. The other
is much tamer and it was us only checking for one type of error from
the IRQ subsystem (when allocating new IRQs) instead of for all of
them.
- Fix an IRQ allocation where we only check for a specific error (-1).
- CVE-2013-0231 / XSA-43. Make xen-pciback rate limit error messages
from xen_pcibk_enable_msi{,x}()"
* tag 'stable/for-linus-3.8-rc6-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/konrad/xen:
xen: fix error handling path if xen_allocate_irq_dynamic fails
xen-pciback: rate limit error messages
Kernel
xen-pciback: rate limit error messages from xen_pcibk_enable_msi{,x}()
kernel_security·2013-02-06·CVSS 4.9
CVE-2013-0231 [MEDIUM] xen-pciback: rate limit error messages from xen_pcibk_enable_msi{,x}()
xen-pciback: rate limit error messages from xen_pcibk_enable_msi{,x}()
... as being guest triggerable (e.g. by invoking
XEN_PCI_OP_enable_msi{,x} on a device not being MSI/MSI-X capable).
This is CVE-2013-0231 / XSA-43.
Also make the two messages uniform in both their wording and severity.
Signed-off-by: Jan Beulich
Acked-by: Ian Campbell
Reviewed-by: Konrad Rzeszutek Wilk
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages
bugzilla·2013-02-13·CVSS 4.9
CVE-2013-0231 [MEDIUM] CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages
CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages
Xen's PCI backend drivers in Linux allow a guest with assigned PCI device(s) to cause a DoS through a flood of kernel messages, potentially affecting other
domains in the system.
A malicious guest with passed through PCI devices can mount a DoS affecting the entire system.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 910878]
---
Statement:
This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
---
This issue has been addressed in following products:
Re
Bugzilla
CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages [fedora-all]
bugzilla·2013-02-13·CVSS 4.9
CVE-2013-0231 [MEDIUM] CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages [fedora-all]
CVE-2013-0231 kernel: xen: pciback DoS via not rate limited log messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this i
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://osvdb.org/89903http://secunia.com/advisories/52059http://www.debian.org/security/2013/dsa-2632http://www.openwall.com/lists/oss-security/2013/02/05/9http://www.securityfocus.com/bid/57740https://exchange.xforce.ibmcloud.com/vulnerabilities/81923http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://osvdb.org/89903http://secunia.com/advisories/52059http://www.debian.org/security/2013/dsa-2632http://www.openwall.com/lists/oss-security/2013/02/05/9http://www.securityfocus.com/bid/57740https://exchange.xforce.ibmcloud.com/vulnerabilities/81923
2013-02-13
Published