CVE-2013-4356 — Missing Release of Memory after Effective Lifetime in XEN
Severity
5.4MEDIUMNVD
EPSS
0.1%
top 73.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 9
Latest updateMay 17
Description
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
CVSS vector
AV:A/AC:M/C:P/I:P/A:PExploitability: 5.5 | Impact: 6.4