Input validation error in Xen - CVE-2006-0744

 

Input validation error in Xen - CVE-2006-0744

Published: April 18, 2006 / Updated: July 28, 2020


Vulnerability identifier: #VU32790
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2006-0744
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.

Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, which causes the kernel exception handler to run on the user stack with the wrong GS.


Affected software

Xen
xen (Alpine package)

How to mitigate CVE-2006-0744

Install update from vendor's website.

xen (Alpine package) - update to 4.1.1-r3

External References

Related Security Bulletins