The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-03-07T02:00:00

Updated: 2024-08-06T14:18:09.452Z

Reserved: 2012-12-06T00:00:00

Link: CVE-2013-0151

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-03-07T05:04:42.060

Modified: 2023-02-13T04:38:03.497

Link: CVE-2013-0151

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-01-22T00:00:00Z

Links: CVE-2013-0151 - Bugzilla