CVE-2013-4361
published 2013-10-01CVE-2013-4361: The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.40%
31.9th percentile
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Kernel: Xen: Xsa-66: information leak through fbld instruction emulation
vendor_redhat·2013-09-30·CVSS 2.1
CVE-2013-4361 [LOW] Kernel: Xen: Xsa-66: information leak through fbld instruction emulation
Kernel: Xen: Xsa-66: information leak through fbld instruction emulation
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Statement: This issue does not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue does not affect the versions of the Linux kernel package as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as it does not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - No
Debian
CVE-2013-4361: xen - The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the corre...
vendor_debian·2013·CVSS 2.1
CVE-2013-4361 [LOW] CVE-2013-4361: xen - The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the corre...
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
GHSA
GHSA-jmgg-m7r5-7296: The fbld instruction emulation in Xen 3
ghsa_unreviewed·2022-05-17
CVE-2013-4361 [LOW] CWE-200 GHSA-jmgg-m7r5-7296: The fbld instruction emulation in Xen 3
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
OSV
CVE-2013-4361: The fbld instruction emulation in Xen 3
osv·2013-10-01·CVSS 2.1
CVE-2013-4361 [LOW] CVE-2013-4361: The fbld instruction emulation in Xen 3
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
bugzilla·2013-09-30·CVSS 1.5
CVE-2013-4355 [LOW] CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
CVE-2013-4355 CVE-2013-4356 CVE-2013-4361 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-4361 Kernel: Xen: Xsa-66: information leak through fbld instruction emulation
bugzilla·2013-09-19·CVSS 2.1
CVE-2013-4361 [LOW] CVE-2013-4361 Kernel: Xen: Xsa-66: information leak through fbld instruction emulation
CVE-2013-4361 Kernel: Xen: Xsa-66: information leak through fbld instruction emulation
The emulation of the fbld instruction (which is used during I/O
emulation) uses the wrong variable for the source effective address.
As a result, the actual address used is an uninitialised bit pattern
from the stack.
A malicious guest might be able to find out information about the
contents of the hypervisor stack, by observing which values are
actually being used by fbld and inferring what the address must have
been. Depending on the actual values on the stack this attack might
be very difficult to carry out.
A malicious guest could use this flaw to access memory bytes related to other
guests.
Discussion:
Statement:
This issue does not affect the versions of the kernel-xen package as shipped with
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00009.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/09/30/3http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00009.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/09/30/3
2013-10-01
Published