0.000
EPSS

CVE-2012-3433

CVSSv4: NA | CVSSv3: NA | CVSSv2: 4.9 | VMScore: 590 | EPSS: 0.00075 | KEV: Not Included
Published: 24/11/2012 Updated: 21/11/2024

Vulnerability Summary

Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.0.0

xen xen 4.1.0

Vendor Advisories

Debian Bug report logs - #683279 CVE-2012-3432 Package: xen; Maintainer for xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Jul 2012 13:27:02 UTC Severity: important Tags: security Fixed in versions xen/401-53, xen/413-1 ...