PT-2012-4761 · Xen+2 · Xen+2

Petr Matousek

·

Publicado

2012-09-14

·

Atualizado

2017-08-29

·

CVE-2012-3496

CVSS v2.0

4.7

Média

VetorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen versions 4.0 through 4.2 Citrix XenServer version 6.0.2 and earlier
Description The issue allows local PV OS guest kernels to cause a denial of service, resulting in a host crash, by triggering a BUG when invalid flags such as MEMF populate on demand are used. This occurs when translating paging mode is not used.
Recommendations For Xen versions 4.0 through 4.2, consider updating to a version where this issue is resolved to prevent local PV OS guest kernels from causing a denial of service. For Citrix XenServer version 6.0.2 and earlier, consider updating to a version where this issue is resolved to prevent local PV OS guest kernels from causing a denial of service. As a temporary workaround, consider restricting the use of invalid flags such as MEMF populate on demand in the XENMEM populate physmap function until a patch is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3496
DSA-2544-1
OPENSUSE-SU-2012_1172-1
OPENSUSE-SU-2012_1174-1
OPENSUSE-SU-2012_1572-1
OPENSUSE-SU-2012_1573-1

Produtos afetados

Citrix Xenserver
Suse
Xen