Xen 'xen_failsafe_callback()' Function Local Denial of Service Vulnerability
BID:57433
Info
Xen 'xen_failsafe_callback()' Function Local Denial of Service Vulnerability
| Bugtraq ID: | 57433 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0190 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 16 2013 12:00AM |
| Updated: | Apr 13 2015 09:46PM |
| Credit: | Andrew Cooper |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 OpenVZ Project OpenVZ 042stab055.10 OpenVZ Project OpenVZ 042stab053.5 OpenVZ Project OpenVZ 042stab049.6 OpenVZ Project OpenVZ 042stab044.17 OpenVZ Project OpenVZ 042stab044.11 OpenVZ Project OpenVZ 042stab039.10 OpenVZ Project OpenVZ 042stab037.1 Linux kernel 3.3.2 Linux kernel 3.2.13 Linux kernel 3.2.9 Linux kernel 3.2.1 Linux kernel 3.1.8 Linux kernel 3.2.2 CentOS CentOS 6 Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
Xen 'xen_failsafe_callback()' Function Local Denial of Service Vulnerability
Xen is prone to a denial-of-service vulnerability.
Local attackers with access to a guest operating system can exploit this issue to crash the guest operating system, effectively denying service to legitimate users.
Xen 2.6.23 is vulnerable; other versions may also be affected.
Xen is prone to a denial-of-service vulnerability.
Local attackers with access to a guest operating system can exploit this issue to crash the guest operating system, effectively denying service to legitimate users.
Xen 2.6.23 is vulnerable; other versions may also be affected.
Exploit / POC
Xen 'xen_failsafe_callback()' Function Local Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen 'xen_failsafe_callback()' Function Local Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Xen 'xen_failsafe_callback()' Function Local Denial of Service Vulnerability
References:
References:
- Bug 896038 - (CVE-2013-0190) CVE-2013-0190 kernel: stack corruption in xen_fail (Red Hat Bugzilla)
- [PATCH] xen: Fix stack corruption in xen_failsafe_callback for 32bit PVOPS guest (Andrew Cooper)
- ChangeLog-3.0.60 (Greg Kroah-Hartman )
- ChangeLog-3.4.27 (Greg Kroah-Hartman )
- Download/kernel/rhel6/042stab075.2 (OpenVZ)
- Download/kernel/rhel6/042stab078.22 (openvz)
- Xen Project Homepage (Xen Project)
- ASA-2013-115: Red Hat Enterprise Linux 6 kernel update (RHSA-2013-0496) (Avaya)