CVE-2012-3432
published 2012-12-03CVE-2012-3432: The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain…
PriorityP49low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.64%
46.5th percentile
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-1 (bookworm) | xen 4.1.3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xen: HVM guest user mode MMIO emulation DoS
vendor_redhat·2012-07-26·CVSS 1.9
CVE-2012-3432 [LOW] kernel: xen: HVM guest user mode MMIO emulation DoS
kernel: xen: HVM guest user mode MMIO emulation DoS
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.
Statement: Not vulnerable.
The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6,
and Red Hat Enterprise MRG are not affected.
The versions of the kernel-xen packages as shipped with Red Hat Enterprise Linux 5 are not affected as they implement a different MMIO emulation mechanism.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel-xen (Red Hat Enterprise Linux 5) -
Debian
CVE-2012-3432: xen - The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator fo...
vendor_debian·2012·CVSS 1.9
CVE-2012-3432 [LOW] CVE-2012-3432: xen - The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator fo...
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: resolved (fixed in 4.1.3-1)
trixie: resolved (fixed in 4.1.3-1)
GHSA
GHSA-rx77-gcq6-838g: The handle_mmio function in arch/x86/hvm/io
ghsa_unreviewed·2022-05-17
CVE-2012-3432 [LOW] GHSA-rx77-gcq6-838g: The handle_mmio function in arch/x86/hvm/io
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.
OSV
CVE-2012-3432: The handle_mmio function in arch/x86/hvm/io
osv·2012-12-03·CVSS 1.9
CVE-2012-3432 [LOW] CVE-2012-3432: The handle_mmio function in arch/x86/hvm/io
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.xen.org/archives/html/xen-devel/2012-07/msg01649.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2531http://www.securityfocus.com/bid/54691http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.xen.org/archives/html/xen-devel/2012-07/msg01649.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2531http://www.securityfocus.com/bid/54691
2012-12-03
Published