CVE-2012-4544
published 2012-10-31CVE-2012-4544: The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.42%
34.0th percentile
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-4 (bookworm) | xen 4.1.3-4 (bookworm) |
| xen | xen | <= 4.2.0 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
| xen | xen | >= 0 < 4.1.3-4 | 4.1.3-4 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5vgr-8hw2-wp3h: The PV domain builder in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2012-4544 [LOW] CWE-20 GHSA-5vgr-8hw2-wp3h: The PV domain builder in Xen 4
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
OSV
CVE-2012-4544: The PV domain builder in Xen 4
osv·2012-10-31·CVSS 2.1
CVE-2012-4544 [LOW] CVE-2012-4544: The PV domain builder in Xen 4
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
Red Hat
xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk
vendor_redhat·2012-10-26·CVSS 2.1
CVE-2012-4544 [LOW] xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk
xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
Package: xen (Red Hat Enterprise Linux Extended Update Support 5.9) - Affected
Debian
CVE-2012-4544: xen - The PV domain builder in Xen 4.2 and earlier does not validate the size of the k...
vendor_debian·2012·CVSS 2.1
CVE-2012-4544 [LOW] CVE-2012-4544: xen - The PV domain builder in Xen 4.2 and earlier does not validate the size of the k...
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
Scope: local
bookworm: resolved (fixed in 4.1.3-4)
bullseye: resolved (fixed in 4.1.3-4)
forky: resolved (fixed in 4.1.3-4)
sid: resolved (fixed in 4.1.3-4)
trixie: resolved (fixed in 4.1.3-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4544 xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk [fedora-all]
bugzilla·2012-10-26·CVSS 2.1
CVE-2012-4544 [LOW] CVE-2012-4544 xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk [fedora-all]
CVE-2012-4544 xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2012-4544 xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk
bugzilla·2012-10-26·CVSS 2.1
CVE-2012-4544 [LOW] CVE-2012-4544 xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk
CVE-2012-4544 xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk
The Xen PV domain builder contained no validation of the size of the supplied kernel or ramdisk either before or after decompression. This could cause the toolstack to consume all available RAM in the domain running the domain builder.
A malicious guest administrator who can supply a kernel or ramdisk can exhaust memory in domain 0 leading to a denial of service attack.
HVM guests are not affected by this vulnerability.
Reference:
http://lists.xen.org/archives/html/xen-devel/2012-10/msg02015.html
http://www.openwall.com/lists/oss-security/2012/10/26/3
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Created xen tracking bugs for this issue
Affects:
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://osvdb.org/86619http://rhn.redhat.com/errata/RHSA-2013-0241.htmlhttp://secunia.com/advisories/51071http://secunia.com/advisories/51324http://secunia.com/advisories/51352http://secunia.com/advisories/51413http://www.debian.org/security/2013/dsa-2636http://www.openwall.com/lists/oss-security/2012/10/26/3http://www.securityfocus.com/bid/56289http://www.securitytracker.com/id?1027699https://exchange.xforce.ibmcloud.com/vulnerabilities/79617http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091832.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/091844.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://osvdb.org/86619http://rhn.redhat.com/errata/RHSA-2013-0241.htmlhttp://secunia.com/advisories/51071http://secunia.com/advisories/51324http://secunia.com/advisories/51352http://secunia.com/advisories/51413http://www.debian.org/security/2013/dsa-2636http://www.openwall.com/lists/oss-security/2012/10/26/3http://www.securityfocus.com/bid/56289http://www.securitytracker.com/id?1027699https://exchange.xforce.ibmcloud.com/vulnerabilities/79617
2012-10-31
Published