4.7
CVSSv2

CVE-2012-5514

Published: 13/12/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The guest_physmap_mark_populate_on_demand function in Xen 4.2 and previous versions does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen

xen xen 4.0.2

xen xen 4.0.1

xen xen 3.3.0

xen xen 3.3.1

xen xen 3.0.4

xen xen 3.0.3

xen xen 4.0.4

xen xen 4.0.3

xen xen 3.4.2

xen xen 3.4.0

xen xen 3.2.0

xen xen 3.1.4

xen xen 3.1.3

xen xen 4.1.1

xen xen 4.1.0

xen xen 4.0.0

xen xen 3.4.3

xen xen 3.3.2

xen xen 3.2.3

xen xen 3.0.2

xen xen 4.1.3

xen xen 4.1.2

xen xen 3.4.4

xen xen 3.4.1

xen xen 3.2.2

xen xen 3.2.1

Vendor Advisories

Multiple denial of service vulnerabilities have been discovered in the Xen Hypervisor One of the issue (CVE-2012-5513) could even lead to privilege escalation from guest to host Some of the recently published Xen Security Advisories (XSA 25 and 28) are not fixed by this update and should be fixed in a future release CVE-2011-3131 (XSA 5): DoS ...