← Back

CVE-2013-4329

nvd nist
Published: Sep 12, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:A/AC:H/Au:S/C:C/I:C/A:C
Exploitability: 2.5 / Impact: 10.0
Source: NVD

Description

The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device before the IOMMU setup is complete, which allows local HVM guest domains to gain privileges or cause a denial of service via a DMA instruction.

Affected (15)

Products: Xen: Xen
1 product
Xen
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Xen
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.1.5
Version 4.2.0
Version 4.2.1
Version 4.2.2
Version 4.2.3

Related CWEs

Timeline

No history available yet.