Back to search
CVE-2010-4255
Published: Jan 25, 2011
Modified: Aug 7, 2024
PUBLISHED
Description
The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console
mailing-list
x_refsource_BUGTRAQ
RHSA-2011:0017
vendor-advisory
x_refsource_REDHAT
46397
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=658155
x_refsource_CONFIRM
[oss-security] 20101130 CVE request: xen: x86-64: don't crash Xen upon direct pv guest access
mailing-list
x_refsource_MLIST
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
x_refsource_CONFIRM
42884
third-party-advisory
x_refsource_SECUNIA
[xen-devel] 20101129 [PATCH] x86-64: don't crash Xen upon direct pv guest access
mailing-list
x_refsource_MLIST
[oss-security] 20101130 Re: CVE request: xen: x86-64: don't crash Xen upon direct pv guest access
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now