Back

MEDIUM

xen: use-after-free in libxl_list_cpupool under memory pressure (XSA-70)

Published Oct 17, 2013

Description

Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary code via unspecified vectors.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the versions of the xen package as shipped with Red Hat Enterprise Linux 5 as it does not provide support for the libxl toolstack. This issue does not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 17, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 10, 2013