Back to search
CVE-2013-1920
Published: Apr 12, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running "under memory pressure" and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain event channel tracking table, which causes a use-after-free and allows local guest kernels to inject arbitrary events and gain privileges via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2014:0470
vendor-advisory
x_refsource_SUSE
55082
third-party-advisory
x_refsource_SECUNIA
GLSA-201309-24
vendor-advisory
x_refsource_GENTOO
92050
vdb-entry
x_refsource_OSVDB
xen-cve20131920-code-exec(83226)
vdb-entry
x_refsource_XF
openSUSE-SU-2013:0912
vendor-advisory
x_refsource_SUSE
52857
third-party-advisory
x_refsource_SECUNIA
58880
vdb-entry
x_refsource_BID
SUSE-SU-2014:0446
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0411
vendor-advisory
x_refsource_SUSE
1028388
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now