CVE-2013-4355
published 2013-10-01CVE-2013-4355: Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory…
PriorityP410low1.5CVSS 2.0
AVLACMAuSCPINAN
EPSS
0.31%
23.0th percentile
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | <= 4.3.0 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.01.5LOWAV:L/AC:M/Au:S/C:P/I:N/A:N
osv1.5LOW
vendor_redhat5.5MEDIUM
vendor_debian1.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85vh-p875-9rm4: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2013-4355 [LOW] CWE-200 GHSA-85vh-p875-9rm4: Xen 4
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
OSV
CVE-2013-4355: Xen 4
osv·2013-10-01·CVSS 1.5
CVE-2013-4355 [LOW] CVE-2013-4355: Xen 4
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
Red Hat
kernel: scsi: bnx2fc: Make bnx2fc_recv_frame() mp safe
vendor_redhat·2024-06-20·CVSS 5.5
CVE-2022-48715 [MEDIUM] CWE-20 kernel: scsi: bnx2fc: Make bnx2fc_recv_frame() mp safe
kernel: scsi: bnx2fc: Make bnx2fc_recv_frame() mp safe
In the Linux kernel, the following vulnerability has been resolved:
scsi: bnx2fc: Make bnx2fc_recv_frame() mp safe
Running tests with a debug kernel shows that bnx2fc_recv_frame() is
modifying the per_cpu lport stats counters in a non-mpsafe way. Just boot
a debug kernel and run the bnx2fc driver with the hardware enabled.
[ 1391.699147] BUG: using smp_processor_id() in preemptible [00000000] code: bnx2fc_
[ 1391.699160] caller is bnx2fc_recv_frame+0xbf9/0x1760 [bnx2fc]
[ 1391.699174] CPU: 2 PID: 4355 Comm: bnx2fc_l2_threa Kdump: loaded Tainted: G B
[ 1391.699180] Hardware name: HP ProLiant DL120 G7, BIOS J01 07/01/2013
[ 1391.699183] Call Trace:
[ 1391.699188] dump_stack_lvl+0x57/0x7d
[ 1391.699198] check_preemption_disabled+0xc8/0xd
Red Hat
Kernel: Xen: Xsa-63: information leak via I/O instruction emulation
vendor_redhat·2013-09-30·CVSS 1.5
CVE-2013-4355 [LOW] CWE-391 Kernel: Xen: Xsa-63: information leak via I/O instruction emulation
Kernel: Xen: Xsa-63: information leak via I/O instruction emulation
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
Statement: This issue does affect the version of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Debian
CVE-2013-4355: xen - Xen 4.3.x and earlier does not properly handle certain errors, which allows loca...
vendor_debian·2013·CVSS 1.5
CVE-2013-4355 [LOW] CVE-2013-4355: xen - Xen 4.3.x and earlier does not properly handle certain errors, which allows loca...
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
bugzilla·2013-09-30·CVSS 1.5
CVE-2013-4355 [LOW] CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-4355 Kernel: Xen: Xsa-63: information leak via I/O instruction emulation
bugzilla·2013-09-18·CVSS 1.5
CVE-2013-4355 [LOW] CVE-2013-4355 Kernel: Xen: Xsa-63: information leak via I/O instruction emulation
CVE-2013-4355 Kernel: Xen: Xsa-63: information leak via I/O instruction emulation
Insufficient or missing error handling in certain routines dealing
with guest memory reads can lead to uninitialized data on the
hypervisor stack (potentially containing sensitive data from prior
work the hypervisor performed) being copied to guest visible storage.
This allows a malicious HVM guest to craft certain operations (namely,
but not limited to, port or memory mapped I/O writes) involving
physical or virtual addresses that have no actual memory associated
with them, so that hypervisor stack contents are copied into the
destination of the operation, thus becoming visible to the guest.
A malicious HVM guest could use this flaw to read data relating to other
guests.
Acknowledgements:
Red Hat would
Bugzilla
CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation
bugzilla·2011-05-09·CVSS 6.9
CVE-2011-4355 [MEDIUM] CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation
CVE-2011-4355 gdb: object file .debug_gdb_scripts section improper input validation
It was discovered [1],[2] the the GNU Debugger (gdb) would load untrusted files from the current working directory when .debug_gdb_scripts was defined. While this was a design decision, it is an insecure one and users who do not pre-inspect untrusted files may execute arbitrary code with their privileges.
[1] http://sourceware.org/ml/gdb-patches/2011-04/msg00559.html
[2] http://sourceware.org/ml/gdb-patches/2011-05/msg00202.html
Discussion:
Created gdb tracking bugs for this issue
Affects: fedora-all [bug 756117]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0522 https://rhn.redhat.com/errata/RHSA-2013-0522.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1790.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/09/30/1http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1790.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/09/30/1
2013-10-01
Published