cbcvebase.
CVE-2012-3432
published 2012-12-03

CVE-2012-3432: The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain…

PriorityP49low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.64%
46.5th percentile
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.1.3-1 (bookworm)xen 4.1.3-1 (bookworm)
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.1.3-14.1.3-1
xenxen>= 0 < 4.1.3-14.1.3-1
xenxen>= 0 < 4.1.3-14.1.3-1
xenxen>= 0 < 4.1.3-14.1.3-1

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.