CVE-2013-4329
12.09.2013, 18:37
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xen | xen | 4.0.0 |
| xen | xen | 4.0.1 |
| xen | xen | 4.0.2 |
| xen | xen | 4.0.3 |
| xen | xen | 4.0.4 |
| xen | xen | 4.1.0 |
| xen | xen | 4.1.1 |
| xen | xen | 4.1.2 |
| xen | xen | 4.1.3 |
| xen | xen | 4.1.4 |
| xen | xen | 4.1.5 |
| xen | xen | 4.2.0 |
| xen | xen | 4.2.1 |
| xen | xen | 4.2.2 |
| xen | xen | 4.2.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References