Upstream information

CVE-2013-4553 at MITRE

Description

The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 5.16
Vector AV:A/AC:M/Au:S/C:N/I:N/A:C
Access Vector Adjacent Network
Access Complexity Medium
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
SUSE Bugzilla entries: 848657 [RESOLVED / FIXED], 849667 [RESOLVED / FIXED], 849668 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP3
  • xen >= 4.2.3_08-0.7.1
  • xen-doc-html >= 4.2.3_08-0.7.1
  • xen-doc-pdf >= 4.2.3_08-0.7.1
  • xen-kmp-default >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-kmp-pae >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-libs >= 4.2.3_08-0.7.1
  • xen-libs-32bit >= 4.2.3_08-0.7.1
  • xen-tools >= 4.2.3_08-0.7.1
  • xen-tools-domU >= 4.2.3_08-0.7.1
Patchnames:
sledsp3-xen-201311
SUSE Linux Enterprise Desktop 12
  • xen >= 4.4.1_06-2.2
  • xen-kmp-default >= 4.4.1_06_k3.12.28_4-2.2
  • xen-libs >= 4.4.1_06-2.2
  • xen-libs-32bit >= 4.4.1_06-2.2
Patchnames:
SUSE Linux Enterprise Desktop 12 GA xen
SUSE Linux Enterprise Desktop 12 SP1
  • xen >= 4.5.1_12-2.3
  • xen-kmp-default >= 4.5.1_12_k3.12.49_11-2.3
  • xen-libs >= 4.5.1_12-2.3
  • xen-libs-32bit >= 4.5.1_12-2.3
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA xen
SUSE Linux Enterprise Desktop 12 SP2
  • xen >= 4.7.0_12-23.4
  • xen-libs >= 4.7.0_12-23.4
  • xen-libs-32bit >= 4.7.0_12-23.4
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA xen
SUSE Linux Enterprise Server 11 SP1-LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-pae >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Patchnames:
slessp1-xen-201402
SUSE Linux Enterprise Server 11 SP2-LTSS
  • xen >= 4.1.6_06-0.5.1
  • xen-devel >= 4.1.6_06-0.5.1
  • xen-doc-html >= 4.1.6_06-0.5.1
  • xen-doc-pdf >= 4.1.6_06-0.5.1
  • xen-kmp-default >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-kmp-pae >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-kmp-trace >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-libs >= 4.1.6_06-0.5.1
  • xen-libs-32bit >= 4.1.6_06-0.5.1
  • xen-tools >= 4.1.6_06-0.5.1
  • xen-tools-domU >= 4.1.6_06-0.5.1
Patchnames:
slessp2-xen-201402
SUSE Linux Enterprise Server 11 SP3
  • xen >= 4.2.3_08-0.7.1
  • xen-doc-html >= 4.2.3_08-0.7.1
  • xen-doc-pdf >= 4.2.3_08-0.7.1
  • xen-kmp-default >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-kmp-pae >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-libs >= 4.2.3_08-0.7.1
  • xen-libs-32bit >= 4.2.3_08-0.7.1
  • xen-tools >= 4.2.3_08-0.7.1
  • xen-tools-domU >= 4.2.3_08-0.7.1
Patchnames:
slessp3-xen-201311
SUSE Linux Enterprise Server 12 SP2
  • xen >= 4.7.0_12-23.4
  • xen-doc-html >= 4.7.0_12-23.4
  • xen-libs >= 4.7.0_12-23.4
  • xen-libs-32bit >= 4.7.0_12-23.4
  • xen-tools >= 4.7.0_12-23.4
  • xen-tools-domU >= 4.7.0_12-23.4
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA xen
SUSE Linux Enterprise Software Development Kit 11 SP3
  • xen-devel >= 4.2.3_08-0.7.1
Patchnames:
sdksp3-xen-201311
SUSE Linux Enterprise Software Development Kit 11 SP3
  • xen-devel >= 4.2.3_08-0.7.1
Builds
SAT Patch Nr: 8588
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
  • xen-kmp-default >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-kmp-pae >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-libs >= 4.2.3_08-0.7.1
  • xen-tools-domU >= 4.2.3_08-0.7.1
Builds
SAT Patch Nr: 8588
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
  • xen >= 4.2.3_08-0.7.1
  • xen-doc-html >= 4.2.3_08-0.7.1
  • xen-doc-pdf >= 4.2.3_08-0.7.1
  • xen-kmp-default >= 4.2.3_08_3.0.101_0.8-0.7.1
  • xen-libs >= 4.2.3_08-0.7.1
  • xen-libs-32bit >= 4.2.3_08-0.7.1
  • xen-tools >= 4.2.3_08-0.7.1
  • xen-tools-domU >= 4.2.3_08-0.7.1
Builds
SAT Patch Nr: 8588
SUSE Linux Enterprise Server 11 SP2 LTSS
  • xen-kmp-default >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-kmp-pae >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-kmp-trace >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-libs >= 4.1.6_06-0.5.1
  • xen-tools-domU >= 4.1.6_06-0.5.1
Builds
SAT Patch Nr: 8964
SUSE Linux Enterprise Server 11 SP2 LTSS
  • xen >= 4.1.6_06-0.5.1
  • xen-doc-html >= 4.1.6_06-0.5.1
  • xen-doc-pdf >= 4.1.6_06-0.5.1
  • xen-kmp-default >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-kmp-trace >= 4.1.6_06_3.0.101_0.7.17-0.5.1
  • xen-libs >= 4.1.6_06-0.5.1
  • xen-libs-32bit >= 4.1.6_06-0.5.1
  • xen-tools >= 4.1.6_06-0.5.1
  • xen-tools-domU >= 4.1.6_06-0.5.1
Builds
SAT Patch Nr: 8964
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-pae >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
openSUSE 12.3
  • xen >= 4.2.4_02-1.26.2
  • xen-debugsource >= 4.2.4_02-1.26.2
  • xen-devel >= 4.2.4_02-1.26.2
  • xen-doc-html >= 4.2.4_02-1.26.2
  • xen-doc-pdf >= 4.2.4_02-1.26.2
  • xen-kmp-default >= 4.2.4_02_k3.7.10_1.28-1.26.2
  • xen-kmp-default-debuginfo >= 4.2.4_02_k3.7.10_1.28-1.26.2
  • xen-kmp-desktop >= 4.2.4_02_k3.7.10_1.28-1.26.2
  • xen-kmp-desktop-debuginfo >= 4.2.4_02_k3.7.10_1.28-1.26.2
  • xen-kmp-pae >= 4.2.4_02_k3.7.10_1.28-1.26.2
  • xen-kmp-pae-debuginfo >= 4.2.4_02_k3.7.10_1.28-1.26.2
  • xen-libs >= 4.2.4_02-1.26.2
  • xen-libs-32bit >= 4.2.4_02-1.26.2
  • xen-libs-debuginfo >= 4.2.4_02-1.26.2
  • xen-libs-debuginfo-32bit >= 4.2.4_02-1.26.2
  • xen-tools >= 4.2.4_02-1.26.2
  • xen-tools-debuginfo >= 4.2.4_02-1.26.2
  • xen-tools-domU >= 4.2.4_02-1.26.2
  • xen-tools-domU-debuginfo >= 4.2.4_02-1.26.2
Patchnames:
openSUSE-2014-271
openSUSE 13.1
  • xen >= 4.3.2_01-12.1
  • xen-debugsource >= 4.3.2_01-12.1
  • xen-devel >= 4.3.2_01-12.1
  • xen-doc-html >= 4.3.2_01-12.1
  • xen-kmp-default >= 4.3.2_01_k3.11.10_7-12.1
  • xen-kmp-default-debuginfo >= 4.3.2_01_k3.11.10_7-12.1
  • xen-kmp-desktop >= 4.3.2_01_k3.11.10_7-12.1
  • xen-kmp-desktop-debuginfo >= 4.3.2_01_k3.11.10_7-12.1
  • xen-kmp-pae >= 4.3.2_01_k3.11.10_7-12.1
  • xen-kmp-pae-debuginfo >= 4.3.2_01_k3.11.10_7-12.1
  • xen-libs >= 4.3.2_01-12.1
  • xen-libs-32bit >= 4.3.2_01-12.1
  • xen-libs-debuginfo >= 4.3.2_01-12.1
  • xen-libs-debuginfo-32bit >= 4.3.2_01-12.1
  • xen-tools >= 4.3.2_01-12.1
  • xen-tools-debuginfo >= 4.3.2_01-12.1
  • xen-tools-domU >= 4.3.2_01-12.1
  • xen-tools-domU-debuginfo >= 4.3.2_01-12.1
  • xen-xend-tools >= 4.3.2_01-12.1
  • xen-xend-tools-debuginfo >= 4.3.2_01-12.1
Patchnames:
openSUSE-2013-968
openSUSE-2014-272
openSUSE 13.2
  • xen >= 4.4.1_06-3.3
  • xen-doc-html >= 4.4.1_06-3.3
  • xen-kmp-default >= 4.4.1_06_k3.16.6_2-3.3
  • xen-kmp-desktop >= 4.4.1_06_k3.16.6_2-3.3
  • xen-libs >= 4.4.1_06-3.3
  • xen-tools >= 4.4.1_06-3.3
  • xen-tools-domU >= 4.4.1_06-3.3
Patchnames:
openSUSE 13.2 GA xen
openSUSE Leap 42.1
  • xen >= 4.5.1_10-1.4
  • xen-doc-html >= 4.5.1_10-1.4
  • xen-kmp-default >= 4.5.1_10_k4.1.12_1-1.4
  • xen-libs >= 4.5.1_10-1.4
  • xen-tools >= 4.5.1_10-1.4
  • xen-tools-domU >= 4.5.1_10-1.4
Patchnames:
openSUSE Leap 42.1 GA xen
openSUSE Leap 42.2
  • xen >= 4.7.0_12-1.6
  • xen-doc-html >= 4.7.0_12-1.6
  • xen-libs >= 4.7.0_12-1.6
  • xen-tools >= 4.7.0_12-1.6
  • xen-tools-domU >= 4.7.0_12-1.6
Patchnames:
openSUSE Leap 42.2 GA xen