LWN.net Logo

xen: denial of service

Package(s):xen CVE #(s):CVE-2012-4544
Created:November 12, 2012 Updated:February 8, 2013
Description: From the CVE entry:

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

Alerts:
Fedora FEDORA-2012-17204 2012-11-09
Fedora FEDORA-2012-17408 2012-11-09
SUSE SUSE-SU-2012:1486-1 2012-11-16
SUSE SUSE-SU-2012:1487-1 2012-11-16
SUSE SUSE-SU-2012:1503-1 2012-11-19
openSUSE openSUSE-SU-2012:1572-1 2012-11-26
openSUSE openSUSE-SU-2012:1573-1 2012-11-26
Red Hat RHSA-2013:0241-01 2013-02-07
CentOS CESA-2013:0241 2013-02-07
Oracle ELSA-2013-0241 2013-02-07
Scientific Linux SL-xen-20130207 2013-02-07
Debian DSA-2636-1 2013-03-01
Debian DSA-2636-2 2013-03-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds