CVE-2013-1919
published 2013-05-13CVE-2013-1919: Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via…
PriorityP416medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.37%
29.4th percentile
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.4-3 (bookworm) | xen 4.1.4-3 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.4-3 | 4.1.4-3 |
| xen | xen | >= 0 < 4.1.4-3 | 4.1.4-3 |
| xen | xen | >= 0 < 4.1.4-3 | 4.1.4-3 |
| xen | xen | >= 0 < 4.1.4-3 | 4.1.4-3 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xen: Several access permission issues with IRQs for unprivileged guests
vendor_redhat·2013-04-18·CVSS 4.7
CVE-2013-1919 [MEDIUM] kernel: xen: Several access permission issues with IRQs for unprivileged guests
kernel: xen: Several access permission issues with IRQs for unprivileged guests
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5 as it has no support for stub domains.
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat
Debian
CVE-2013-1919: xen - Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows loca...
vendor_debian·2013·CVSS 4.7
CVE-2013-1919 [MEDIUM] CVE-2013-1919: xen - Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows loca...
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
Scope: local
bookworm: resolved (fixed in 4.1.4-3)
bullseye: resolved (fixed in 4.1.4-3)
forky: resolved (fixed in 4.1.4-3)
sid: resolved (fixed in 4.1.4-3)
trixie: resolved (fixed in 4.1.4-3)
GHSA
GHSA-h9vg-xq6f-567v: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2013-1919 [MEDIUM] GHSA-h9vg-xq6f-567v: Xen 4
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
OSV
CVE-2013-1919: Xen 4
osv·2013-05-13·CVSS 4.7
CVE-2013-1919 [MEDIUM] CVE-2013-1919: Xen 4
Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to IRQs and cause a denial of service via vectors related to "passed-through IRQs or PCI devices."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1919 kernel: xen: Several access permission issues with IRQs for unprivileged guests [fedora-all]
bugzilla·2013-04-18·CVSS 4.7
CVE-2013-1919 [MEDIUM] CVE-2013-1919 kernel: xen: Several access permission issues with IRQs for unprivileged guests [fedora-all]
CVE-2013-1919 kernel: xen: Several access permission issues with IRQs for unprivileged guests [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-1919 kernel: xen: Several access permission issues with IRQs for unprivileged guests
bugzilla·2013-04-10·CVSS 4.7
CVE-2013-1919 [MEDIUM] CVE-2013-1919 kernel: xen: Several access permission issues with IRQs for unprivileged guests
CVE-2013-1919 kernel: xen: Several access permission issues with IRQs for unprivileged guests
Various IRQ related access control operations may not have the intended effect, thus potentially permitting a stub domain to gran its client domain access to an IRQ it doesn't have access to itself.
Malicious or buggy stub domains kernels can mount a denial of service attack possibly affecting the whole system.
Only Xen systems using stub domains are vulnerable.
Only HVM guests with passed-through IRQs or PCI devices are able to exploit the vulnerability.
Acknowledgements:
Red Hat would like to thank the Xen for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5 as it has
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104537.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/104538.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00049.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2013/dsa-2662http://www.openwall.com/lists/oss-security/2013/04/18/6http://www.securityfocus.com/bid/59292http://lists.fedoraproject.org/pipermail/package-announce/2013-May/104537.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/104538.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00049.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2013/dsa-2662http://www.openwall.com/lists/oss-security/2013/04/18/6http://www.securityfocus.com/bid/59292
2013-05-13
Published