CVE-2013-4329

Xen 4.0.x-4.2.x - Privilege Escalation or Denial of Service via DMA Instruction

Title source: llm
STIX 2.1

Description

The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/09/10/4
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201407-03.xml
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-3006

Scores

EPSS 0.0016
EPSS Percentile 36.6%

Details

CWE
CWE-264
Status published
Products (15)
xen/xen 4.0.0
xen/xen 4.0.1
xen/xen 4.0.2
xen/xen 4.0.3
xen/xen 4.0.4
xen/xen 4.1.0
xen/xen 4.1.1
xen/xen 4.1.2
xen/xen 4.1.3
xen/xen 4.1.4
... and 5 more
Published Sep 12, 2013
Tracked Since Feb 18, 2026