CVE-2013-1917
Published: 13 May 2013
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hypervisor crash) by triggering a #GP fault, which is not properly handled by another IRET instruction.
Notes
Author | Note |
---|---|
mdeslaur | hypervisor packages are in universe. For issues in the hypervisor, add appropriate tags to each section, ex: Tags_xen: universe-binary |
seth-arnold | only 64-bit paravirtualized guests on Intel CPUs |
Priority
Status
Package | Release | Status |
---|---|---|
xen Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Released
(4.1.2-2ubuntu2.8)
|
|
quantal |
Released
(4.1.3-3ubuntu1.5)
|
|
raring |
Released
(4.2.1-0ubuntu3.1)
|
|
saucy |
Released
(4.2.1-0ubuntu3.1)
|
|
upstream |
Needed
|
|
Patches: upstream: http://lists.xen.org/archives/html/xen-announce/2013-04/binGS8guTt3VO.bin upstream: http://lists.xen.org/archives/html/xen-announce/2013-04/binEL_7UvL5vH.bin upstream: http://lists.xen.org/archives/html/xen-announce/2013-04/binGlTcGmAZhQ.bin upstream: http://lists.xen.org/archives/html/xen-announce/2013-04/binswL9iUJWNc.bin |
||
Binaries built from this source package are in Universe and so are supported by the community. | ||
xen-3.1 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needed
|
|
xen-3.2 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needed
|
|
xen-3.3 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Ignored
(end of life)
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needed
|
|
Binaries built from this source package are in Universe and so are supported by the community. |