Input validation error in Xen - CVE-2006-0744

 

Input validation error in Xen - CVE-2006-0744

Published: April 18, 2006 / Updated: July 28, 2020


Vulnerability identifier: #VU32790
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2006-0744
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Xen
Software vendor:
Xen Project

Description

The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.

Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.


Remediation

Install update from vendor's website.

External links