Lucene search

K
xenXen ProjectXSA-26
HistoryDec 03, 2012 - 5:51 p.m.

Grant table version switch list corruption vulnerability

2012-12-0317:51:00
Xen Project
xenbits.xen.org
38

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.001

Percentile

28.1%

ISSUE DESCRIPTION

Downgrading the grant table version of a guest involves freeing its status pages. This freeing was incomplete - the page(s) are freed back to the allocator, but not removed from the domain’s tracking list. This would cause list corruption, eventually leading to a hypervisor crash.

IMPACT

A malicious guest administrator can cause Xen to crash, leading to a denial of service attack.

VULNERABLE SYSTEMS

All Xen version from 4.0 on are vulnerable.
Version 3.4 and earlier are not vulnerable.

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.001

Percentile

28.1%