[XSA-42] Linux kernel hits general protection if %ds is corrupt for 32-bit PVOPS.
Severity
Medium
CVEs
1
ISSUE DESCRIPTION
Linux kernel when returning from an iret assumes that %ds segment is safe
and uses it to reference various per-cpu related fields. Unfortunately
the user can modify the LDT and provide a NULL one. Whenever an iret is called
we end up in xen_iret and try to use the %ds segment and cause an
general protection fault.
IMPACT
Malicious or buggy unprivileged user space can cause the guest kernel to
crash, or permit a privilege escalation within the guest, or operate
erroneously.
VULNERABLE SYSTEMS
All 32bit PVOPS versions of Linux are affected, since the introduction
of Xen PVOPS support in 2.6.23. Classic-Xen kernels are not vulnerable.
- ID
- XSA-42
- Severity
- medium
- Severity from
- CVE-2013-0228
- URL
- http://xenbits.xen.org/xsa/advisory-42.html
- Published
-
2013-02-12T12:00:00
(11 years ago) - Modified
-
2013-02-12T12:00:00
(11 years ago) - Rights
- Xen Project
- Other Advisories
-
- ELSA-2013-0630
- ELSA-2013-2507
- FEDORA-2013-10695
- FEDORA-2013-12530
- FEDORA-2013-12990
- FEDORA-2013-13536
- FEDORA-2013-15151
- FEDORA-2013-16336
- FEDORA-2013-17010
- FEDORA-2013-17942
- FEDORA-2013-18364
- FEDORA-2013-18822
- FEDORA-2013-20748
- FEDORA-2013-21822
- FEDORA-2013-22695
- FEDORA-2013-2597
- FEDORA-2013-2635
- FEDORA-2013-2728
- FEDORA-2013-3086
- FEDORA-2013-3106
- FEDORA-2013-3223
- FEDORA-2013-3630
- FEDORA-2013-3893
- FEDORA-2013-3909
- FEDORA-2013-4012
- FEDORA-2013-4240
- FEDORA-2013-4357
- FEDORA-2013-5368
- FEDORA-2013-6041
- FEDORA-2013-6537
- FEDORA-2013-6999
- FEDORA-2013-9123
- RHSA-2013:0630
- USN-1756-1
- USN-1760-1
- USN-1767-1
- USN-1778-1
- USN-1781-1
- USN-1795-1
- USN-1796-1
- USN-1797-1
- USN-1805-1
- USN-1808-1
Source | # ID | Name | URL |
---|---|---|---|
Xen Project | XSA-42 | Security Advisory | http://xenbits.xen.org/xsa/advisory-42.html |
Xen Project | XSA-42 | Signed Security Advisory | http://xenbits.xen.org/xsa/advisory-42.txt |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |