CVE-2012-4537
published 2012-11-21CVE-2012-4537: Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.43%
35.1th percentile
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-4 (bookworm) | xen 4.1.3-4 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3g8-h8w3-8hqm: Xen 3
ghsa_unreviewed·2022-05-17
CVE-2012-4537 [LOW] GHSA-m3g8-h8w3-8hqm: Xen 3
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."
OSV
CVE-2012-4537: Xen 3
osv·2012-11-21·CVSS 2.1
CVE-2012-4537 [LOW] CVE-2012-4537: Xen 3
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."
Red Hat
kernel: xen: Memory mapping failure can crash Xen
vendor_redhat·2012-11-13·CVSS 2.1
CVE-2012-4537 [LOW] kernel: xen: Memory mapping failure can crash Xen
kernel: xen: Memory mapping failure can crash Xen
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."
Statement: This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Debian
CVE-2012-4537: xen - Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchroniz...
vendor_debian·2012·CVSS 2.1
CVE-2012-4537 [LOW] CVE-2012-4537: xen - Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchroniz...
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
sid: resolved (fixed in 4.1.3-4)
trixie: resolved (fixed in 4.1.3-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4537 kernel: xen: Memory mapping failure can crash Xen [fedora-all]
bugzilla·2012-11-13·CVSS 2.1
CVE-2012-4537 [LOW] CVE-2012-4537 kernel: xen: Memory mapping failure can crash Xen [fedora-all]
CVE-2012-4537 kernel: xen: Memory mapping failure can crash Xen [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
Bugzilla
CVE-2012-4537 kernel: xen: Memory mapping failure can crash Xen
bugzilla·2012-10-25·CVSS 2.1
CVE-2012-4537 [LOW] CVE-2012-4537 kernel: xen: Memory mapping failure can crash Xen
CVE-2012-4537 kernel: xen: Memory mapping failure can crash Xen
When set_p2m_entry fails, Xen's internal data structures (the p2m and m2p tables) can get out of sync. This failure can be triggered by unusual guest behaviour exhausting the memory reserved for the p2m table. If it happens, subsequent guest-invoked memory operations can cause Xen to fail an assertion and crash.
A malicious HVM guest administrator might be able to cause Xen to crash.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hyperviso
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-11/msg00005.htmlhttp://osvdb.org/87307http://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://secunia.com/advisories/51200http://secunia.com/advisories/51324http://secunia.com/advisories/51352http://secunia.com/advisories/51413http://secunia.com/advisories/51468http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2582http://www.openwall.com/lists/oss-security/2012/11/13/6http://www.securityfocus.com/bid/56498http://www.securitytracker.com/id?1027761https://exchange.xforce.ibmcloud.com/vulnerabilities/80024https://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-11/msg00005.htmlhttp://osvdb.org/87307http://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://secunia.com/advisories/51200http://secunia.com/advisories/51324http://secunia.com/advisories/51352http://secunia.com/advisories/51413http://secunia.com/advisories/51468http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://www.debian.org/security/2012/dsa-2582http://www.openwall.com/lists/oss-security/2012/11/13/6http://www.securityfocus.com/bid/56498http://www.securitytracker.com/id?1027761https://exchange.xforce.ibmcloud.com/vulnerabilities/80024https://security.gentoo.org/glsa/201604-03
2012-11-21
Published