CVE-2013-1432
Published: 28 August 2013
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.
Notes
Author | Note |
---|---|
mdeslaur | hypervisor packages are in universe. For issues in the hypervisor, add appropriate tags to each section, ex: Tags_xen: universe-binary |
seth-arnold | Incomplete / incorrect fix for CVE-2013-1918 |
mdeslaur | This is XSA-58 4.1 and 4.2 only |
Priority
Status
Package | Release | Status |
---|---|---|
xen Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Released
(4.1.5-0ubuntu0.12.04.2)
|
|
quantal |
Released
(4.1.5-0ubuntu0.12.10.2)
|
|
raring |
Released
(4.2.2-0ubuntu0.13.04.3)
|
|
saucy |
Not vulnerable
(4.3.0-1ubuntu1)
|
|
upstream |
Needed
|
|
Patches: upstream: http://lists.xen.org/archives/html/xen-announce/2013-06/bin0uIuC2YjWL.bin upstream: http://lists.xen.org/archives/html/xen-announce/2013-06/binHR6AHtI4mk.bin |
||
Binaries built from this source package are in Universe and so are supported by the community. | ||
xen-3.3 Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
Binaries built from this source package are in Universe and so are supported by the community. |