cbcvebase.
CVE-2013-2076
published 2013-08-28

CVE-2013-2076: Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is…

PriorityP413medium4.3CVSS 2.0
AVAACHAuSCCINAN
EPSS
0.50%
39.2th percentile
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianxen< xen 4.8.0~rc3-1 (bookworm)xen 4.8.0~rc3-1 (bookworm)
debianxen< xen 4.2.2-1 (bookworm)xen 4.2.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
oraclevm_server
oraclevm_server
xenxen<= 4.4.0
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.8.0~rc3-14.8.0~rc3-1
xenxen>= 0 < 4.2.2-14.2.2-1
xenxen>= 0 < 4.8.0~rc3-14.8.0~rc3-1

CVSS provenance

nvdv2.04.3MEDIUMAV:A/AC:H/Au:S/C:C/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.