CVE-2013-2076
published 2013-08-28CVE-2013-2076: Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is…
PriorityP413medium4.3CVSS 2.0
AVAACHAuSCCINAN
EPSS
0.50%
39.2th percentile
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| debian | xen | < xen 4.2.2-1 (bookworm) | xen 4.2.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| xen | xen | <= 4.4.0 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.2.2-1 | 4.2.2-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:A/AC:H/Au:S/C:C/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3158 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3159 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2016-3158: xen - The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle wri...
vendor_debian·2016·CVSS 4.3
CVE-2016-3158 [MEDIUM] CVE-2016-3158: xen - The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle wri...
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
Debian
CVE-2016-3159: xen - The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle ...
vendor_debian·2016·CVSS 4.3
CVE-2016-3159 [MEDIUM] CVE-2016-3159: xen - The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle ...
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
Red Hat
kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
vendor_redhat·2013-06-03·CVSS 2.1
CVE-2013-2076 [LOW] kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect R
Debian
CVE-2013-2076: xen - Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore...
vendor_debian·2013·CVSS 2.1
CVE-2013-2076 [LOW] CVE-2013-2076: xen - Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore...
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
Scope: local
bookworm: resolved (fixed in 4.2.2-1)
bullseye: resolved (fixed in 4.2.2-1)
forky: resolved (fixed in 4.2.2-1)
sid: resolved (fixed in 4.2.2-1)
trixie: resolved (fixed in 4.2.2-1)
GHSA
GHSA-86c3-896f-hgp9: Xen 4
ghsa_unreviewed·2022-05-17·CVSS 2.1
CVE-2013-2076 [LOW] CWE-200 GHSA-86c3-896f-hgp9: Xen 4
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
GHSA
GHSA-96jh-8f37-hfp8: The xrstor function in arch/x86/xstate
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2016-3158 [MEDIUM] CWE-200 GHSA-96jh-8f37-hfp8: The xrstor function in arch/x86/xstate
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
GHSA
GHSA-h55q-7cr6-wwr6: The fpu_fxrstor function in arch/x86/i387
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2016-3159 [MEDIUM] CWE-200 GHSA-h55q-7cr6-wwr6: The fpu_fxrstor function in arch/x86/i387
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
OSV
CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387
osv·2016-04-13·CVSS 4.3
CVE-2016-3159 [MEDIUM] CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
OSV
CVE-2016-3158: The xrstor function in arch/x86/xstate
osv·2016-04-13·CVSS 4.3
CVE-2016-3158 [MEDIUM] CVE-2016-3158: The xrstor function in arch/x86/xstate
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
OSV
CVE-2013-2076: Xen 4
osv·2013-08-28·CVSS 2.1
CVE-2013-2076 [LOW] CVE-2013-2076: Xen 4
Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2076 kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs [fedora-all]
bugzilla·2013-06-03·CVSS 4.3
CVE-2013-2076 [MEDIUM] CVE-2013-2076 kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs [fedora-all]
CVE-2013-2076 kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: th
Bugzilla
CVE-2013-2076 kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
bugzilla·2013-05-17·CVSS 4.3
CVE-2013-2076 [MEDIUM] CVE-2013-2076 kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
CVE-2013-2076 kernel: xen: Information leak on XSAVE/XRSTOR capable AMD CPUs
On AMD processors supporting XSAVE/XRSTOR (family 15h and up), when an exception is pending, these instructions save/restore only the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR. This allows one domain to determine portions of the state of floating point instructions of other domains.
A malicious domain may be able to leverage this to obtain sensitive information such as cryptographic keys from another domain.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and R
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/06/03/1http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/06/03/1
2013-08-28
Published