MEDIUM
kernel: xen: Linux netback DoS via malicious guest ring.
Published Feb 18, 2013
5.2
MEDIUMCVSS 2.0
EPSS 0.56%
Description
Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.
Affected products
No data.
OR
- ≤ 3.7.8
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.21
- 3.0.22
- 3.0.23
- 3.0.24
- 3.0.25
- 3.0.26
- 3.0.27
- 3.0.28
- 3.0.29
- 3.0.30
- 3.0.31
- 3.0.32
- 3.0.33
- 3.0.34
- 3.0.35
- 3.0.36
- 3.0.37
- 3.0.38
- 3.0.39
- 3.0.40
- 3.0.41
- 3.0.42
- 3.0.43
- 3.0.44
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.6
- 3.1.7
- 3.1.8
- 3.1.9
- 3.1.10
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.2.13
- 3.2.14
- 3.2.15
- 3.2.16
- 3.2.17
- 3.2.18
- 3.2.19
- 3.2.20
- 3.2.21
- 3.2.22
- 3.2.23
- 3.2.24
- 3.2.25
- 3.2.26
- 3.2.27
- 3.2.28
- 3.2.29
- 3.2.30
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.10
- 3.4.11
- 3.4.12
- 3.4.13
- 3.4.14
- 3.4.15
- 3.4.16
- 3.4.17
- 3.4.18
- 3.4.19
- 3.4.20
- 3.4.21
- 3.4.22
- 3.4.23
- 3.4.24
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.6.9
- 3.6.10
- 3.6.11
- 3.7
- 3.7.1
- 3.7.2
- 3.7.3
- 3.7.4
- 3.7.5
- 3.7.6
- 3.7.7
No data.
Red Hat Enterprise Linux 5
kernel-xen
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-xen | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7d5145d8eb2b9791533ffe4dc003b129b9696c48 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:176 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2013/02/05/12 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2013-0217 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=910883 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0251 Advisory
- https://github.com/torvalds/linux/commit/7d5145d8eb2b9791533ffe4dc003b129b9696c48 x_refsource_CONFIRMPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-0217
- https://www.cve.org/CVERecord?id=CVE-2013-0217
| Link | Providers | Tags |
|---|---|---|
| http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7d5145d8eb2b9791533ffe4dc003b129b9696c48 | x_refsource_CONFIRM | |
| http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8 | x_refsource_CONFIRM | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2013:176 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.openwall.com/lists/oss-security/2013/02/05/12 | mailing-listx_refsource_MLIST | |
| https://access.redhat.com/security/cve/CVE-2013-0217 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=910883 | x_refsource_CONFIRMIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0251 | Advisory | |
| https://github.com/torvalds/linux/commit/7d5145d8eb2b9791533ffe4dc003b129b9696c48 | x_refsource_CONFIRMPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-0217 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-0217 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 18, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
Link CVE-2013-0217
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-0251 Assigner redhat
Published Feb 18, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-0251