CVE-2012-4535
published 2012-11-21CVE-2012-4535: Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU…
PriorityP48low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.39%
30.8th percentile
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-4 (bookworm) | xen 4.1.3-4 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjmp-9gj7-24m6: Xen 3
ghsa_unreviewed·2022-05-17
CVE-2012-4535 [LOW] GHSA-cjmp-9gj7-24m6: Xen 3
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
OSV
CVE-2012-4535: Xen 3
osv·2012-11-21·CVSS 1.9
CVE-2012-4535 [LOW] CVE-2012-4535: Xen 3
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
Red Hat
kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
vendor_redhat·2012-11-13·CVSS 1.9
CVE-2012-4535 [LOW] kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
Statement: This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Debian
CVE-2012-4535: xen - Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS admini...
vendor_debian·2012·CVSS 1.9
CVE-2012-4535 [LOW] CVE-2012-4535: xen - Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS admini...
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
sid: resolved (fixed in 4.1.3-4)
trixie: resolved (fixed in 4.1.3-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4535 kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog [fedora-all]
bugzilla·2012-11-13·CVSS 1.9
CVE-2012-4535 [LOW] CVE-2012-4535 kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog [fedora-all]
CVE-2012-4535 kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2012-4535 kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
bugzilla·2012-10-25·CVSS 1.9
CVE-2012-4535 [LOW] CVE-2012-4535 kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
CVE-2012-4535 kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
A guest which sets a VCPU with an inappropriate deadline can cause an infinite loop in Xen, blocking the affected physical CPU indefinitely.
A malicious guest administrator can trigger the bug. If the Xen watchdog is enabled, the whole system will crash. Otherwise the guest can cause the system to become completely unresponsive.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
---
Created xen tra
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-11/msg00001.htmlhttp://osvdb.org/87298http://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://secunia.com/advisories/51200http://secunia.com/advisories/51324http://secunia.com/advisories/51352http://secunia.com/advisories/51413http://secunia.com/advisories/51468http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2582http://www.openwall.com/lists/oss-security/2012/11/13/1http://www.securityfocus.com/bid/56498http://www.securitytracker.com/id?1027759https://exchange.xforce.ibmcloud.com/vulnerabilities/80022https://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-11/msg00001.htmlhttp://osvdb.org/87298http://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://secunia.com/advisories/51200http://secunia.com/advisories/51324http://secunia.com/advisories/51352http://secunia.com/advisories/51413http://secunia.com/advisories/51468http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2582http://www.openwall.com/lists/oss-security/2012/11/13/1http://www.securityfocus.com/bid/56498http://www.securitytracker.com/id?1027759https://exchange.xforce.ibmcloud.com/vulnerabilities/80022https://security.gentoo.org/glsa/201604-03
2012-11-21
Published