CVE-2012-0218
published 2012-12-03CVE-2012-0218: Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception…
PriorityP48low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.40%
31.9th percentile
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm) | xen 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
| xen | xen | >= 0 < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 | 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j3pq-42jm-m8p4: Xen 3
ghsa_unreviewed·2022-05-04
CVE-2012-0218 [LOW] GHSA-j3pq-42jm-m8p4: Xen 3
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.
OSV
CVE-2012-0218: Xen 3
osv·2012-12-03·CVSS 1.9
CVE-2012-0218 [LOW] CVE-2012-0218: Xen 3
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.
Red Hat
kernel: xen: guest denial of service on syscall/sysenter exception generation
vendor_redhat·2012-06-12·CVSS 1.9
CVE-2012-0218 [LOW] kernel: xen: guest denial of service on syscall/sysenter exception generation
kernel: xen: guest denial of service on syscall/sysenter exception generation
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5 as we did not have support for sysenter and compat (32bit) version of syscall instructions for PV guests running on the Xen hypervisor (introduced in upstream changeset 16207:aeebd173c3fa).
This issue did not affect the ve
Debian
CVE-2012-0218: xen - Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a sysc...
vendor_debian·2012·CVSS 1.9
CVE-2012-0218 [LOW] CVE-2012-0218: xen - Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a sysc...
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.
Scope: local
bookworm: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
bullseye: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
forky: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
sid: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
trixie: resolved (fixed in 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1)
No detection rules found.
No public exploits indexed.
http://lists.xen.org/archives/html/xen-announce/2012-06/msg00003.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2501http://lists.xen.org/archives/html/xen-announce/2012-06/msg00003.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2501
2012-12-03
Published