CVE-2013-6375
published 2013-11-23CVE-2013-6375: Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows…
PriorityP431high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
1.39%
69.2th percentile
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| opensuse | opensuse | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
osv7.9HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2xpm-w5mr-rm8m: Xen 4
ghsa_unreviewed·2022-05-14
CVE-2013-6375 [HIGH] GHSA-2xpm-w5mr-rm8m: Xen 4
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
OSV
CVE-2013-6375: Xen 4
osv·2013-11-23·CVSS 7.9
CVE-2013-6375 [HIGH] CVE-2013-6375: Xen 4
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
Red Hat
xen: Insufficient TLB flushing in VT-d (iommu) code
vendor_redhat·2013-11-20·CVSS 7.9
CVE-2013-6375 [HIGH] xen: Insufficient TLB flushing in VT-d (iommu) code
xen: Insufficient TLB flushing in VT-d (iommu) code
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-6375: xen - Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properl...
vendor_debian·2013·CVSS 7.9
CVE-2013-6375 [HIGH] CVE-2013-6375: xen - Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properl...
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6375 xen: Insufficient TLB flushing in VT-d (iommu) code
bugzilla·2013-11-21·CVSS 7.9
CVE-2013-6375 [HIGH] CVE-2013-6375 xen: Insufficient TLB flushing in VT-d (iommu) code
CVE-2013-6375 xen: Insufficient TLB flushing in VT-d (iommu) code
An inverted boolean parameter resulted in TLB flushes not happening upon clearing of a present translation table entry. Retaining stale TLB entries could allow guests access to memory that ought to have
been revoked, or grant greater access than intended.
Malicious guest administrators might be able to cause host-wide denial of service, or escalate their privilege to that of the host.
References:
http://seclists.org/oss-sec/2013/q4/322
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Lin
Bugzilla
CVE-2013-6375 xen: Insufficient TLB flushing in VT-d (iommu) code [fedora-all]
bugzilla·2013-11-21·CVSS 7.9
CVE-2013-6375 [HIGH] CVE-2013-6375 xen: Insufficient TLB flushing in VT-d (iommu) code [fedora-all]
CVE-2013-6375 xen: Insufficient TLB flushing in VT-d (iommu) code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
http://lists.opensuse.org/opensuse-updates/2013-12/msg00059.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2013/11/20/3http://www.openwall.com/lists/oss-security/2013/11/21/1http://www.securitytracker.com/id/1029369http://lists.opensuse.org/opensuse-updates/2013-12/msg00059.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2013/11/20/3http://www.openwall.com/lists/oss-security/2013/11/21/1http://www.securitytracker.com/id/1029369
2013-11-23
Published