CVE Database
/

CVE-2013-1920

Back to search

CVE-2013-1920

Published: Apr 12, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running "under memory pressure" and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain event channel tracking table, which causes a use-after-free and allows local guest kernels to inject arbitrary events and gain privileges via unspecified vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2014:0470
vendor-advisory
x_refsource_SUSE
55082
third-party-advisory
x_refsource_SECUNIA
GLSA-201309-24
vendor-advisory
x_refsource_GENTOO
92050
vdb-entry
x_refsource_OSVDB
xen-cve20131920-code-exec(83226)
vdb-entry
x_refsource_XF
openSUSE-SU-2013:0912
vendor-advisory
x_refsource_SUSE
52857
third-party-advisory
x_refsource_SECUNIA
58880
vdb-entry
x_refsource_BID
SUSE-SU-2014:0446
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0411
vendor-advisory
x_refsource_SUSE
1028388
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now