Information disclosure in Xen - CVE-2013-1442

 

Information disclosure in Xen - CVE-2013-1442

Published: October 1, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32625
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1442
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.


Affected software

Xen
xen (Alpine package)

How to mitigate CVE-2013-1442

Install update from vendor's website.

xen (Alpine package) - update to 4.3.0-r8

External References

Related Security Bulletins