CVE-2013-1442

NameCVE-2013-1442
DescriptionXen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCPU after touching other restored extended registers, which allows local guest OSes to obtain sensitive information by reading the registers.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3006-1
NVD severitylow (attack range: local)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xen (PTS)wheezy4.1.4-3+deb7u9fixed
wheezy (security)4.1.6.1-1+deb7u1fixed
jessie4.4.1-9+deb8u4fixed
jessie (security)4.4.1-9+deb8u5fixed
stretch, sid4.6.0-1+nmu2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xensource(unstable)4.4.0-1low
xensourcesqueeze(unfixed)end-of-life
xensourcewheezy4.1.4-3+deb7u2lowDSA-3006-1

Notes

[squeeze] - xen <end-of-life> (Unsupported in squeeze-lts)
advisory say: In Xen 4.0.2 through 4.0.4 as well as in Xen 4.1.x XSAVE support is disabled by default

Search for package or bug name: Reporting problems