cbcvebase.
CVE-2012-2625
published 2012-10-31

CVE-2012-2625: The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of…

PriorityP49low2.7CVSS 2.0
AVAACLAuSCNINAP
EPSS
0.92%
56.3th percentile
The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.1.3-4 (bookworm)xen 4.1.3-4 (bookworm)
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.1.3-44.1.3-4
xenxen>= 0 < 4.1.3-44.1.3-4
xenxen>= 0 < 4.1.3-44.1.3-4
xenxen>= 0 < 4.1.3-44.1.3-4
xenxen-unstable< 25589\:60f09d1ab1fe25589\:60f09d1ab1fe

CVSS provenance

nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv2.7LOW
vendor_debian2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.