Candidate: CVE-2013-2078 PublicDate: 2013-08-14 15:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2078 http://lists.xen.org/archives/html/xen-announce/2013-06/msg00000.html Description: Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction. Ubuntu-Description: Notes: seth-arnold> adding "no-xsave" to supervisor mitigates against the problem mdeslaur> This is XSA-54 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_xen-3.3: upstream_xen-3.3: ignored (reached end-of-life) lucid_xen-3.3: not-affected precise_xen-3.3: DNE quantal_xen-3.3: DNE raring_xen-3.3: DNE devel_xen-3.3: DNE Patches_xen: upstream: http://lists.xen.org/archives/html/xen-announce/2013-06/bin_A0ey2XISB.bin Tags_xen: universe-binary upstream_xen: needed lucid_xen: DNE precise_xen: released (4.1.2-2ubuntu2.9) quantal_xen: released (4.1.3-3ubuntu1.6) raring_xen: released (4.2.1-0ubuntu3.2) devel_xen: released (4.2.1-0ubuntu4)