CVE-2013-4356
published 2013-10-09CVE-2013-4356: Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local…
PriorityP417medium5.4CVSS 2.0
AVAACMAuNCPIPAP
EPSS
0.61%
45.2th percentile
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration
vendor_redhat·2013-09-30·CVSS 5.4
CVE-2013-4356 [MEDIUM] CWE-401 Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration
Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
Statement: This issue does not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue does not affect the versions of the Linux kernel package as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as it does not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-4356: xen - Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migr...
vendor_debian·2013·CVSS 5.4
CVE-2013-4356 [MEDIUM] CVE-2013-4356: xen - Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migr...
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
GHSA
GHSA-c4mh-mf74-4fcf: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2013-4356 [MEDIUM] GHSA-c4mh-mf74-4fcf: Xen 4
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
OSV
CVE-2013-4356: Xen 4
osv·2013-10-09·CVSS 5.4
CVE-2013-4356 [MEDIUM] CVE-2013-4356: Xen 4
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
bugzilla·2013-09-30·CVSS 1.5
CVE-2013-4355 [LOW] CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-4356 Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration
bugzilla·2013-09-18·CVSS 5.4
CVE-2013-4356 [MEDIUM] CVE-2013-4356 Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration
CVE-2013-4356 Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration
On some hardware, during live migration of 64-bit PV guests, some
parts of the guest's shadow pagetables are mistakenly filled in with
hypervisor mappings. This causes Xen to crash when those mappings are
later cleared. Before the crash, a malicious guest could use
hypercalls to cause Xen to read and write the parts of memory pointed
to by the stray mappings.
A malicious 64-bit PV guest, on a vulnerable host system, that can arrange for
itself to be live migrated could use this flaw to read or write memory at the
high physical addresses on the host.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
This issue does not affect the versions
http://secunia.com/advisories/54962http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2013/09/30/2http://www.securityfocus.com/bid/62709http://secunia.com/advisories/54962http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2013/09/30/2http://www.securityfocus.com/bid/62709
2013-10-09
Published