6.1
CVSSv2

CVE-2010-4255

Published: 25/01/2011 Updated: 10/10/2018
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
VMScore: 543
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and previous versions on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.

Vulnerable Product Search on Vulmon Subscribe to Product

citrix xen 3.1.3

citrix xen 3.1.4

citrix xen 3.2.2

citrix xen 3.3.2

citrix xen 3.0.2

citrix xen 3.0.4

citrix xen 3.3.1

citrix xen 3.4.1

citrix xen 3.2.0

citrix xen 3.2.1

citrix xen 3.1.2

citrix xen 3.2.3

citrix xen 3.4.2

citrix xen 4.0.0

citrix xen

citrix xen 3.0.3

citrix xen 3.3.0

citrix xen 3.4.0

citrix xen 3.4.3

Vendor Advisories

Debian Bug report logs - #609531 CVE-2010-4255: 64-bit PV xen guest can crash host by accessing hypervisor per-domain memory area Package: xen; Maintainer for xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 10 Jan 2011 12:03:02 UTC ...