Xen Linux netback Local Denial of Service Vulnerability
Release date:
Updated on: 2013-02-27
Affected Systems:
XenSource Xen
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57743
CVE (CAN) ID: CVE-2013-0216
Xen is an open-source Virtual Machine monitor developed by the University of Cambridge.
The Xen netback implementation includes several defects. Using a guest can cause DoS In the backend domain, which may affect other domains in the system.
The cause of a Cve-2013-0216 vulnerability is that integrity checks fail on the ring producer/consumer pointer, which causes a guest to put netback in a loop for a long time, this will cause netback to be unable to do other work, that is, DOS.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 910883
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XenSource
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://xen.xensource.com/