CVE-2013-2078

Publication date 14 August 2013

Last updated 24 July 2024


Ubuntu priority

Description

Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.

Read the notes from the security team

Status

Package Ubuntu Release Status
xen 13.04 raring
Fixed 4.2.1-0ubuntu3.2
12.10 quantal
Fixed 4.1.3-3ubuntu1.6
12.04 LTS precise
Fixed 4.1.2-2ubuntu2.9
10.04 LTS lucid Not in release
xen-3.3 13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid
Not affected

Notes


seth-arnold

adding "no-xsave" to supervisor mitigates against the problem


mdeslaur

This is XSA-54

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
xen