CVE-2013-4494
published 2013-11-02CVE-2013-4494: Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with…
PriorityP417medium5.2CVSS 2.0
AVAACMAuSCNINAC
EPSS
0.67%
47.8th percentile
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | 4.1.0 – 4.1.6.1 | — |
| xen | xen | 4.2.0 – 4.2.5 | — |
| xen | xen | 4.3.0 – 4.3.4 | — |
CVSS provenance
nvdv2.05.2MEDIUMAV:A/AC:M/Au:S/C:N/I:N/A:C
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xen: Lock order reversal between page allocation and grant table locks
vendor_redhat·2013-11-01·CVSS 5.2
CVE-2013-4494 [MEDIUM] kernel: xen: Lock order reversal between page allocation and grant table locks
kernel: xen: Lock order reversal between page allocation and grant table locks
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
Statement: This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-4494: xen - Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_t...
vendor_debian·2013·CVSS 5.2
CVE-2013-4494 [MEDIUM] CVE-2013-4494: xen - Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_t...
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
GHSA
GHSA-r35f-92wf-6vvc: Xen before 4
ghsa_unreviewed·2022-05-14
CVE-2013-4494 [MEDIUM] CWE-20 GHSA-r35f-92wf-6vvc: Xen before 4
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
OSV
CVE-2013-4494: Xen before 4
osv·2013-11-02·CVSS 5.2
CVE-2013-4494 [MEDIUM] CVE-2013-4494: Xen before 4
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4494 kernel: xen: Lock order reversal between page allocation and grant table locks
bugzilla·2013-11-04·CVSS 5.2
CVE-2013-4494 [MEDIUM] CVE-2013-4494 kernel: xen: Lock order reversal between page allocation and grant table locks
CVE-2013-4494 kernel: xen: Lock order reversal between page allocation and grant table locks
The locks page_alloc_lock and grant_table.lock are not always taken in the same order. This opens the possibility of deadlock. As a result, a malicious guest administrator can deny service to the entire host.
References:
http://seclists.org/oss-sec/2013/q4/204
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1026248]
---
Statement:
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
---
xen-4.3.1-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
xen-4.2.3-7
Bugzilla
CVE-2013-4494 kernel: xen: Lock order reversal between page allocation and grant table locks [fedora-all]
bugzilla·2013-11-04·CVSS 5.2
CVE-2013-4494 [MEDIUM] CVE-2013-4494 kernel: xen: Lock order reversal between page allocation and grant table locks [fedora-all]
CVE-2013-4494 kernel: xen: Lock order reversal between page allocation and grant table locks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00059.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0108.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/11/01/2http://www.openwall.com/lists/oss-security/2013/11/01/3http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00059.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0108.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2013/11/01/2http://www.openwall.com/lists/oss-security/2013/11/01/3
2013-11-02
Published