CVE-2013-2077

Publication date 28 August 2013

Last updated 24 July 2024


Ubuntu priority

Description

Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.

Read the notes from the security team

Status

Package Ubuntu Release Status
xen 13.04 raring
Fixed 4.2.1-0ubuntu3.2
12.10 quantal
Fixed 4.1.3-3ubuntu1.6
12.04 LTS precise
Fixed 4.1.2-2ubuntu2.9
10.04 LTS lucid Not in release
xen-3.3 13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid
Not affected

Notes


seth-arnold

adding "no-xsave" to supervisor mitigates against the problem


mdeslaur

This is XSA-53

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
xen

Access our resources on patching vulnerabilities