LWN.net Logo

Xen: multiple vulnerabilities

Package(s):Xen CVE #(s):CVE-2012-3494 CVE-2012-3495 CVE-2012-3496 CVE-2012-3498 CVE-2012-3516
Created:September 7, 2012 Updated:September 18, 2012
Description:

From the SUSE advisory:

A malicious guest could cause a crash on the host which leads to a Denial of Service (CVE-2012-3494).

A memory corruption related to PHYSDEVOP_get_free_pirq function could lead to a Denial of Service of the host or potentially to execution of arbitrary code (CVE-2012-3495).

A BUG can be triggered via calling functions with invalid flags which causes a Denial of Service (host crash) (CVE-2012-3496).

A malicious guest kernel could crash the host or potentially read hypervisor or guest memory (CVE-2012-3498).

Unspecified vulnerability (CVE-2012-3516).

Alerts:
SUSE SUSE-SU-2012:1133-1 2012-09-07
Debian DSA-2544-1 2012-09-08
SUSE SUSE-SU-2012:1135-1 2012-09-07
openSUSE openSUSE-SU-2012:1174-1 2012-09-14
openSUSE openSUSE-SU-2012:1172-1 2012-09-14
SUSE SUSE-SU-2012:1162-1 2012-09-13
Fedora FEDORA-2012-13443 2012-09-17
openSUSE openSUSE-SU-2012:1572-1 2012-11-26
openSUSE openSUSE-SU-2012:1573-1 2012-11-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds