Description
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2636-1 | xen security update |
Debian DSA |
DSA-2636-2 | xen regression update |
EUVD |
EUVD-2012-4472 | The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T20:42:54.912Z
Reserved: 2012-08-21T00:00:00.000Z
Link: CVE-2012-4544
No data.
Status : Modified
Published: 2012-10-31T16:55:05.827
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-4544
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD