4.7
CVSSv2

CVE-2013-1918

Published: 13/05/2013 Updated: 19/04/2014
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and previous versions are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.1.1

xen xen 4.1.0

xen xen 4.1.3

xen xen 4.1.2

xen xen 4.1.4

xen xen 4.1.5

xen xen 4.2.1

xen xen 4.2.2

xen xen 4.2.0

Vendor Advisories

Multiple vulnerabilities have been discovered in the Xen hypervisor The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-1918 (XSA 45) several long latency operations are not preemptible Some page table manipulation operations for PV guests were not made preemptible, allowing a malicious or buggy ...
Certain page table manipulation operations in Xen 41x, 42x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal" ...