CVE-2013-4494 — Improper Input Validation in XEN
Severity
5.2MEDIUMNVD
EPSS
0.3%
top 46.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 2
Latest updateMay 14
Description
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
CVSS vector
AV:A/AC:M/C:N/I:N/A:CExploitability: 4.4 | Impact: 6.9
Affected Packages3 packages
Also affects: Debian Linux 7.0