Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the realloc function fails, which allows local users to cause a denial of service (heap corruption and crash) and possibly execute arbitrary code via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-10-17T23:00:00
Updated: 2024-08-06T16:38:02.180Z
Reserved: 2013-06-12T00:00:00
Link: CVE-2013-4371
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-10-17T23:55:04.547
Modified: 2024-11-21T01:55:26.580
Link: CVE-2013-4371
Redhat