CVE-2013-1442
published 2013-09-30CVE-2013-1442: Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the…
PriorityP48low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.37%
29.5th percentile
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xen: information leak on AVX and/or LWP capable CPUs
vendor_redhat·2013-09-24·CVSS 1.2
CVE-2013-1442 [LOW] kernel: xen: information leak on AVX and/or LWP capable CPUs
kernel: xen: information leak on AVX and/or LWP capable CPUs
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 as we did not have support for Xen hypervisor.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Packag
Debian
CVE-2013-1442: xen - Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly cle...
vendor_debian·2013·CVSS 1.2
CVE-2013-1442 [LOW] CVE-2013-1442: xen - Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly cle...
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
GHSA
GHSA-pq8f-m2fp-4jv5: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2013-1442 [LOW] CWE-200 GHSA-pq8f-m2fp-4jv5: Xen 4
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
OSV
CVE-2013-1442: Xen 4
osv·2013-09-30·CVSS 1.2
CVE-2013-1442 [LOW] CVE-2013-1442: Xen 4
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
Kernel
HID: zeroplus: validate output report details
kernel_security·2013-09-11·CVSS 4.7
CVE-2013-2889 [MEDIUM] HID: zeroplus: validate output report details
HID: zeroplus: validate output report details
The zeroplus HID driver was not checking the size of allocated values
in fields it used. A HID device could send a malicious output report
that would cause the driver to write beyond the output report allocation
during initialization, causing a heap overflow:
[ 1442.728680] usb 1-1: New USB device found, idVendor=0c12, idProduct=0005
...
[ 1466.243173] BUG kmalloc-192 (Tainted: G W ): Redzone overwritten
CVE-2013-2889
Signed-off-by: Kees Cook
Cc: [email protected]
Reviewed-by: Benjamin Tissoires
Signed-off-by: Jiri Kosina
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1442 kernel: xen: information leak on AVX and/or LWP capable CPUs [fedora-all]
bugzilla·2013-09-25·CVSS 1.2
CVE-2013-1442 [LOW] CVE-2013-1442 kernel: xen: information leak on AVX and/or LWP capable CPUs [fedora-all]
CVE-2013-1442 kernel: xen: information leak on AVX and/or LWP capable CPUs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-1442 kernel: xen: information leak on AVX and/or LWP capable CPUs
bugzilla·2013-09-10·CVSS 1.2
CVE-2013-1442 [LOW] CVE-2013-1442 kernel: xen: information leak on AVX and/or LWP capable CPUs
CVE-2013-1442 kernel: xen: information leak on AVX and/or LWP capable CPUs
When a guest increases the set of extended state components for a vCPU saved/restored via XSAVE/XRSTOR (to date this can only be the upper halves of YMM registers, or AMD's LWP state) after already having touched other extended registers restored via XRSTOR (e.g. floating point or XMM ones) during its current scheduled CPU quantum, the hypervisor would make those registers accessible without discarding the values an earlier scheduled vCPU may have left in them.
A malicious domain may be able to leverage this to obtain sensitive information such as cryptographic keys from another domain.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerabl
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00009.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/09/25/2http://www.securitytracker.com/id/1029090http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00009.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/09/25/2http://www.securitytracker.com/id/1029090
2013-09-30
Published