0.000
EPSS

CVE-2012-5510

CVSSv4: NA | CVSSv3: NA | CVSSv2: 4.7 | VMScore: 570 | EPSS: 0.00092 | KEV: Not Included
Published: 13/12/2012 Updated: 21/11/2024

Vulnerability Summary

Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.0.0

xen xen 4.0.1

xen xen 4.0.2

xen xen 4.0.3

xen xen 4.0.4

xen xen 4.1.0

xen xen 4.1.1

xen xen 4.1.2

xen xen 4.1.3

xen xen 4.2.0

Vendor Advisories

Multiple denial of service vulnerabilities have been discovered in the Xen Hypervisor One of the issue (CVE-2012-5513) could even lead to privilege escalation from guest to host Some of the recently published Xen Security Advisories (XSA 25 and 28) are not fixed by this update and should be fixed in a future release CVE-2011-3131 (XSA 5): DoS ...

References

NVD-CWE-Otherhttps://nvd.nist.govhttps://www.debian.org/security/./dsa-2582https://www.first.org/epsshttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00052.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51468http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.debian.org/security/2012/dsa-2582http://www.openwall.com/lists/oss-security/2012/12/03/6http://www.osvdb.org/88128http://www.securityfocus.com/bid/56794https://exchange.xforce.ibmcloud.com/vulnerabilities/80478http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00052.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51468http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.debian.org/security/2012/dsa-2582http://www.openwall.com/lists/oss-security/2012/12/03/6http://www.osvdb.org/88128http://www.securityfocus.com/bid/56794https://exchange.xforce.ibmcloud.com/vulnerabilities/80478