SB2013070101 - Resource management error in xen (Alpine package)
Published: July 1, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2013-1432)
The vulnerability allows a remote #AU# to execute arbitrary code.
Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows local PV guest kernels to cause a denial of service (premature page free and hypervisor crash) or possibly gain privileges via unspecified vectors.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=14e8058dddb5be40c29deb267ffbc23171991c7a
- https://git.alpinelinux.org/aports/commit/?id=f87a9718398452ab5e15eccd2eb427d16098c072
- https://git.alpinelinux.org/aports/commit/?id=ccdb8c3a1257db6b1ceb3af663b239003a047fd3
- https://git.alpinelinux.org/aports/commit/?id=02b9902f054427e1abb33ff073d866be0c332d70