CVE-2013-4356Missing Release of Memory after Effective Lifetime in XEN

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 73.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 9
Latest updateMay 17

Description

Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).

CVSS vector

AV:A/AC:M/C:P/I:P/A:PExploitability: 5.5 | Impact: 6.4

Affected Packages3 packages

debiandebian/xen< xen 4.4.0-1 (bookworm)
Debianxen/xen< 4.4.0-1+3
NVDxen/xen4.3.0

🔴Vulnerability Details

2
GHSA
GHSA-c4mh-mf74-4fcf: Xen 42022-05-17
OSV
CVE-2013-4356: Xen 42013-10-09

📋Vendor Advisories

2
Red Hat
Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration2013-09-30
Debian
CVE-2013-4356: xen - Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migr...2013

💬Community

2
Bugzilla
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]2013-09-30
Bugzilla
CVE-2013-4356 Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration2013-09-18