Xen Instruction Emulation During VM Exits Denial of Service Vulnerabilities
BID:48610
Info
Xen Instruction Emulation During VM Exits Denial of Service Vulnerabilities
| Bugtraq ID: | 48610 |
| Class: | Design Error |
| CVE: |
CVE-2011-1780 CVE-2011-1936 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 07 2011 12:00AM |
| Updated: | May 27 2013 02:54PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
XenSource Xen 0 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE SUSE Linux Enterprise SDK 10 SP3 SuSE SUSE Linux Enterprise Desktop 10 SP4 RedHat Enterprise Linux 5.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server OpenVZ Project OpenVZ 2.6.32-feoktistov.1 OpenVZ Project OpenVZ 2.6.32 OpenVZ Project OpenVZ 028stab091.1 OpenVZ Project OpenVZ 028stab089.1 OpenVZ Project OpenVZ 028stab085.2 OpenVZ Project OpenVZ 028stab081.1 OpenVZ Project OpenVZ 023stab054.1 OpenVZ Project OpenVZ 023stab053.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
OpenVZ Project OpenVZ 028stab092.2 Avaya Aura Communication Manager Utility Services 6.2 |
Discussion
Xen Instruction Emulation During VM Exits Denial of Service Vulnerabilities
Xen is prone to multiple denial-of-service vulnerabilities.
Attackers can exploit these issues to cause the guest and host operating systems to crash, denying service to legitimate users.
Xen is prone to multiple denial-of-service vulnerabilities.
Attackers can exploit these issues to cause the guest and host operating systems to crash, denying service to legitimate users.
Exploit / POC
Xen Instruction Emulation During VM Exits Denial of Service Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen Instruction Emulation During VM Exits Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Xen Instruction Emulation During VM Exits Denial of Service Vulnerabilities
References:
References:
- CVE-2011-1780 kernel: xen: svm: insufficiencies in handling emulated instruction (Red Hat)
- CVE-2011-1780, CVE-2011-1936, kernel/xen issues (Eugene)
- CVE-2011-1936 kernel: xen: vmx: insecure cpuid vmexit (Red Hat)
- Download/kernel/rhel5/028stab092.2 (OpenVZ)
- XenSource Homepage (XenSource)
- ASA-2011-238 kernel security and bug fix update (RHSA-2011-0927) (Avaya)
- ASA-2011-258 kernel security and bug fix update (RHSA-2011-1065 and RHSA-2011-11 (Avaya)