cbcvebase.
CVE-2013-4494
published 2013-11-02

CVE-2013-4494: Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with…

PriorityP417medium5.2CVSS 2.0
AVAACMAuSCNINAC
EPSS
0.67%
47.8th percentile
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianxen< xen 4.4.0-1 (bookworm)xen 4.4.0-1 (bookworm)
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen>= 0 < 4.4.0-14.4.0-1
xenxen4.1.0 – 4.1.6.1
xenxen4.2.0 – 4.2.5
xenxen4.3.0 – 4.3.4

CVSS provenance

nvdv2.05.2MEDIUMAV:A/AC:M/Au:S/C:N/I:N/A:C
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.