Upstream information
Description
Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 4.7 |
Vector | AV:L/AC:M/Au:N/C:N/I:N/A:C |
Access Vector | Local |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Complete |
SUSE Security Advisories:
- SUSE-SU-2013:1075-1, published Tue Jun 25 11:04:14 MDT 2013
- SUSE-SU-2013:1314-1, published Fri Aug 9 08:04:11 MDT 2013 openSUSE-SU-2013:1392-1 openSUSE-SU-2013:1404-1
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Linux Enterprise Desktop 11 SP2 |
| Patchnames: sdksp2-xen-201305 sledsp2-xen-201305 |
SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Server for SAP Applications 11 SP4 SUSE Linux Enterprise Software Development Kit 11 SP4 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 11 SP4 GA xen-devel-4.4.2_08-1.7 |
SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server for SAP Applications 11 SP2 |
| Patchnames: sdksp2-xen-201305 slessp2-xen-201305 |
SUSE Linux Enterprise Server 11 SP4 |
| Patchnames: SUSE Linux Enterprise Server 11 SP4 GA xen-4.4.2_08-1.7 SUSE Linux Enterprise Software Development Kit 11 SP4 GA xen-devel-4.4.2_08-1.7 |
SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Patchnames: sdksp2-xen-201305 |
SUSE Timeline for this CVE
CVE page created: Wed May 1 08:38:09 2019CVE page last modified: Thu Dec 7 13:12:58 2023