CVE-2013-1935
published 2013-07-16CVE-2013-1935: A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement…
PriorityP420medium5.7CVSS 2.0
AVAACMAuNCNINAC
EPSS
0.49%
38.7th percentile
A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement the PV EOI feature, which allows guest OS users to cause a denial of service (host OS crash) by leveraging a time window during which interrupts are disabled but copy_to_user function calls are possible.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.05.7MEDIUMAV:A/AC:M/Au:N/C:N/I:N/A:C
vendor_debian5.7LOW
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: kvm: pv_eoi guest updates with interrupts disabled
vendor_redhat·2013-06-10·CVSS 5.7
CVE-2013-1935 [MEDIUM] kernel: kvm: pv_eoi guest updates with interrupts disabled
kernel: kvm: pv_eoi guest updates with interrupts disabled
A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement the PV EOI feature, which allows guest OS users to cause a denial of service (host OS crash) by leveraging a time window during which interrupts are disabled but copy_to_user function calls are possible.
Statement: This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue does not affect the versions of KVM package as shipped with Red Hat Enterprise Linux 5.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: realtime
Debian
CVE-2013-1935: linux - A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32...
vendor_debian·2013·CVSS 5.7
CVE-2013-1935 [MEDIUM] CVE-2013-1935: linux - A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32...
A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement the PV EOI feature, which allows guest OS users to cause a denial of service (host OS crash) by leveraging a time window during which interrupts are disabled but copy_to_user function calls are possible.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-3rfm-4g97-5f9p: A certain Red Hat patch to the KVM subsystem in the kernel package before 2
ghsa_unreviewed·2022-05-14
CVE-2013-1935 [MEDIUM] CWE-362 GHSA-3rfm-4g97-5f9p: A certain Red Hat patch to the KVM subsystem in the kernel package before 2
A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement the PV EOI feature, which allows guest OS users to cause a denial of service (host OS crash) by leveraging a time window during which interrupts are disabled but copy_to_user function calls are possible.
No detection rules found.
No public exploits indexed.
2013-07-16
Published