CVE-2013-4375

Related Vulnerabilities: CVE-2013-4375  

The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.

The MITRE CVE dictionary describes this issue as:

The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.

Find out more about CVE-2013-4375 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable.

This issue does not affect the versions of the xen package as shipped with Red Hat Enterprise Linux 5 as it does not provide support for the qdisk PV backend.

This issue does not affect the versions of qemu-kvm as shipped with Red Hat Enterprise Linux 6 as they did not include the upstream commit that introduced this flaw.

This issue does not affect Red Hat Enterprise MRG 2.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 2.3
Base Metrics AV:A/AC:M/Au:S/C:N/I:N/A:P
Access Vector Adjacent Network
Access Complexity Medium
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 qemu-kvm Not affected
Red Hat Enterprise Linux 6 qemu-kvm Not affected
Red Hat Enterprise Linux 5 kernel-xen Not affected

Acknowledgements

Red Hat would like to thank the Xen project for reporting this issue.

External References