CVE-2012-3433
published 2012-11-24CVE-2012-3433: Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.42%
33.7th percentile
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-1 (bookworm) | xen 4.1.3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
| xen | xen | >= 0 < 4.1.3-1 | 4.1.3-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xen: HVM guest destroy p2m teardown host DoS vulnerability
vendor_redhat·2012-08-09·CVSS 4.9
CVE-2012-3433 [MEDIUM] kernel: xen: HVM guest destroy p2m teardown host DoS vulnerability
kernel: xen: HVM guest destroy p2m teardown host DoS vulnerability
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
Statement: Not vulnerable.
The versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6,
and Red Hat Enterprise MRG are not affected.
The versions of the kernel-xen packages as shipped with Red Hat Enterprise Linux 5 are not affected because we did not provide support for memory sharing functionality.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6)
Debian
CVE-2012-3433: xen - Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (...
vendor_debian·2012·CVSS 4.9
CVE-2012-3433 [MEDIUM] CVE-2012-3433: xen - Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (...
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
Scope: local
bookworm: resolved (fixed in 4.1.3-1)
bullseye: resolved (fixed in 4.1.3-1)
forky: resolved (fixed in 4.1.3-1)
sid: resolved (fixed in 4.1.3-1)
trixie: resolved (fixed in 4.1.3-1)
GHSA
GHSA-4r2q-mgcp-7w6w: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2012-3433 [MEDIUM] GHSA-4r2q-mgcp-7w6w: Xen 4
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
OSV
CVE-2012-3433: Xen 4
osv·2012-11-24·CVSS 4.9
CVE-2012-3433 [MEDIUM] CVE-2012-3433: Xen 4
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.xen.org/archives/html/xen-devel/2012-08/msg00855.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2531http://www.openwall.com/lists/oss-security/2012/08/09/3http://www.securityfocus.com/bid/54942http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.xen.org/archives/html/xen-devel/2012-08/msg00855.htmlhttp://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2531http://www.openwall.com/lists/oss-security/2012/08/09/3http://www.securityfocus.com/bid/54942
2012-11-24
Published