HIGH · 7.4

CVE-2013-1432

Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (pr...

Vulnerability Description

Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.

CVSS Score

7.4

HIGH

AV:A/AC:M/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
XenXen4.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1432?

CVE-2013-1432 is a vulnerability with a CVSS score of 7.4 (HIGH). Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (pr...

How severe is CVE-2013-1432?

CVE-2013-1432 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1432?

Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen.