CVE-2011-2901
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
01/10/2013
Last modified:
11/04/2025
Description
Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.
Impact
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | 3.3.0 (including) | |
cpe:2.3:o:xen:xen:3.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.0.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.1.3:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.1.4:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.2.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.2.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:xen:xen:3.2.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://rhn.redhat.com/errata/RHSA-2011-1212.html
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- http://www.openwall.com/lists/oss-security/2011/09/02/2
- https://bugzilla.redhat.com/show_bug.cgi?id=728042
- http://rhn.redhat.com/errata/RHSA-2011-1212.html
- http://secunia.com/advisories/55082
- http://security.gentoo.org/glsa/glsa-201309-24.xml
- http://www.openwall.com/lists/oss-security/2011/09/02/2
- https://bugzilla.redhat.com/show_bug.cgi?id=728042