Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 497084 (CVE-2013-4553)

Summary: <app-emulation/xen-{4.2.3-r1,4.3.1-r5}: Lock order reversal between page_alloc_lock and mm_rwlock (XSA-74) (CVE-2013-4553)
Product: Gentoo Security Reporter: Chris Reffett (RETIRED) <creffett>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: minor CC: idella4, xen
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
See Also:
Whiteboard: B3 [glsa]
Package list:
Runtime testing required: ---

Description Chris Reffett (RETIRED) gentoo-dev Security 2014-01-05 02:26:00 UTC
From ${URL}:


The locks page_alloc_lock and mm_rwlock are not always taken in
the same order.  This raises the possibility of deadlock.

The incorrect order occurs only in the implementation of the
deprecated domctl hypercall XEN_DOMCTL_getmemlist.


A malicious guest administrator may be able to deny service to the
entire host.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2014-01-05 02:28:21 UTC
Patches available at, see the bottom of the page.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2014-01-05 02:29:07 UTC
CVE-2013-4553 (
  The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly
  4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same
  order, which allows local guest administrators to cause a denial of service
  (host deadlock).
Comment 3 Yixun Lan gentoo-dev 2014-01-17 02:15:03 UTC
update status here, the fix already in following versions
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-01-17 17:23:35 UTC
Please advise when ready for stabilization on those version.
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2014-05-21 03:24:46 UTC
Fixed as part of Bug 500530.

Adding to existing GLSA.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-07-16 16:46:31 UTC
This issue was resolved and addressed in
 GLSA 201407-03 at
by GLSA coordinator Mikle Kolyada (Zlogene).