CVE-2013-4494

CVSS v2.0 5.2 (Medium)
52% Progress
EPSS 0.06 % (27th)
0.06% Progress
Affected Products 2
Advisories 26

Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-11-02 18:55:03
(11 years ago)
Updated Date
2018-12-13 17:49:40
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Xen from 4.1.0 version and 4.1.6.1 and prior versions cpe:2.3:o:xen:xen >= 4.1.0 <= 4.1.6.1
  Xen from 4.2.0 version and 4.2.5 and prior versions cpe:2.3:o:xen:xen >= 4.2.0 <= 4.2.5
  Xen from 4.3.0 version and 4.3.4 and prior versions cpe:2.3:o:xen:xen >= 4.3.0 <= 4.3.4

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...