CVE Vulnerabilities

CVE-2012-3432

Published: Dec 03, 2012 | Modified: Oct 11, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
LOW

The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.

Affected Software

Name Vendor Start Version End Version
Xen Xen 3.3.0 (including) 3.3.0 (including)
Xen Xen 4.0.0 (including) 4.0.0 (including)
Xen Xen 4.0.1 (including) 4.0.1 (including)
Xen Xen 4.0.2 (including) 4.0.2 (including)
Xen Xen 4.0.3 (including) 4.0.3 (including)
Xen Xen 4.0.4 (including) 4.0.4 (including)
Xen Xen 4.1.0 (including) 4.1.0 (including)
Xen Xen 4.1.1 (including) 4.1.1 (including)
Xen Xen 4.1.2 (including) 4.1.2 (including)
Xen Xen 4.1.3 (including) 4.1.3 (including)
Xen Xen 4.2.0 (including) 4.2.0 (including)
Xen Ubuntu oneiric *
Xen Ubuntu precise *
Xen Ubuntu upstream *
Xen-3.3 Ubuntu lucid *
Xen-3.3 Ubuntu natty *

References