CVE-2013-2078
Published: 14 August 2013
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.
Notes
Author | Note |
---|---|
seth-arnold | adding "no-xsave" to supervisor mitigates against the problem |
mdeslaur | This is XSA-54 |
Priority
Status
Package | Release | Status |
---|---|---|
xen Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Released
(4.1.2-2ubuntu2.9)
|
|
quantal |
Released
(4.1.3-3ubuntu1.6)
|
|
raring |
Released
(4.2.1-0ubuntu3.2)
|
|
upstream |
Needed
|
|
Patches: upstream: http://lists.xen.org/archives/html/xen-announce/2013-06/bin_A0ey2XISB.bin |
||
Binaries built from this source package are in Universe and so are supported by the community. | ||
xen-3.3 Launchpad, Ubuntu, Debian |
lucid |
Not vulnerable
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
upstream |
Ignored
(end of life)
|