SB2013070102 - Buffer overflow in xen (Alpine package)
Published: July 1, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2013-1918)
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV kernels to cause a denial of service via vectors related to "deep page table traversal."
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=14e8058dddb5be40c29deb267ffbc23171991c7a
- https://git.alpinelinux.org/aports/commit/?id=f87a9718398452ab5e15eccd2eb427d16098c072
- https://git.alpinelinux.org/aports/commit/?id=ccdb8c3a1257db6b1ceb3af663b239003a047fd3
- https://git.alpinelinux.org/aports/commit/?id=02b9902f054427e1abb33ff073d866be0c332d70