Candidate: CVE-2013-1952 PublicDate: 2013-05-13 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1952 http://lists.xen.org/archives/html/xen-announce/2013-05/msg00001.html Description: Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors. Ubuntu-Description: Notes: mdeslaur> hypervisor packages are in universe. For mdeslaur> issues in the hypervisor, add appropriate mdeslaur> tags to each section, ex: mdeslaur> Tags_xen: universe-binary seth-arnold> only 4.0 are newer are affected mdeslaur> This is XSA-49 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_xen-3.1: upstream_xen-3.1: ignored (reached end-of-life) hardy_xen-3.1: ignored (reached end-of-life) lucid_xen-3.1: DNE oneiric_xen-3.1: DNE precise_xen-3.1: DNE quantal_xen-3.1: DNE raring_xen-3.1: DNE devel_xen-3.1: DNE Patches_xen-3.2: upstream_xen-3.2: ignored (reached end-of-life) hardy_xen-3.2: ignored (reached end-of-life) lucid_xen-3.2: DNE oneiric_xen-3.2: DNE precise_xen-3.2: DNE quantal_xen-3.2: DNE raring_xen-3.2: DNE devel_xen-3.2: DNE Patches_xen-3.3: upstream_xen-3.3: ignored (reached end-of-life) hardy_xen-3.3: DNE lucid_xen-3.3: not-affected oneiric_xen-3.3: DNE precise_xen-3.3: DNE quantal_xen-3.3: DNE raring_xen-3.3: DNE devel_xen-3.3: DNE Tags_xen: universe-binary Patches_xen: upstream: http://lists.xen.org/archives/html/xen-announce/2013-05/binnJE8wZL20i.bin (4.1) upstream: http://lists.xen.org/archives/html/xen-announce/2013-05/bin1oiXvD5GIa.bin (4.2) upstream_xen: needed hardy_xen: DNE lucid_xen: DNE oneiric_xen: ignored (reached end-of-life) precise_xen: released (4.1.2-2ubuntu2.9) quantal_xen: released (4.1.3-3ubuntu1.6) raring_xen: released (4.2.1-0ubuntu3.2) devel_xen: released (4.2.1-0ubuntu4)