Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 497084 (CVE-2013-4553) - <app-emulation/xen-{4.2.3-r1,4.3.1-r5}: Lock order reversal between page_alloc_lock and mm_rwlock (XSA-74) (CVE-2013-4553)
Summary: <app-emulation/xen-{4.2.3-r1,4.3.1-r5}: Lock order reversal between page_allo...
Alias: CVE-2013-4553
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: B3 [glsa]
Depends on:
Reported: 2014-01-05 02:26 UTC by Chris Reffett (RETIRED)
Modified: 2014-07-16 16:46 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Chris Reffett (RETIRED) gentoo-dev Security 2014-01-05 02:26:00 UTC
From ${URL}:


The locks page_alloc_lock and mm_rwlock are not always taken in
the same order.  This raises the possibility of deadlock.

The incorrect order occurs only in the implementation of the
deprecated domctl hypercall XEN_DOMCTL_getmemlist.


A malicious guest administrator may be able to deny service to the
entire host.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2014-01-05 02:28:21 UTC
Patches available at, see the bottom of the page.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2014-01-05 02:29:07 UTC
CVE-2013-4553 (
  The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly
  4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same
  order, which allows local guest administrators to cause a denial of service
  (host deadlock).
Comment 3 Yixun Lan archtester gentoo-dev 2014-01-17 02:15:03 UTC
update status here, the fix already in following versions
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2014-01-17 17:23:35 UTC
Please advise when ready for stabilization on those version.
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2014-05-21 03:24:46 UTC
Fixed as part of Bug 500530.

Adding to existing GLSA.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-07-16 16:46:31 UTC
This issue was resolved and addressed in
 GLSA 201407-03 at
by GLSA coordinator Mikle Kolyada (Zlogene).