CVE-2012-6333
published 2012-12-13CVE-2012-6333: Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.40%
31.9th percentile
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.1.3-8 (bookworm) | xen 4.1.3-8 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-8 | 4.1.3-8 |
| xen | xen | >= 0 < 4.1.3-8 | 4.1.3-8 |
| xen | xen | >= 0 < 4.1.3-8 | 4.1.3-8 |
| xen | xen | >= 0 < 4.1.3-8 | 4.1.3-8 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-32g2-hc9h-69wc: Multiple HVM control operations in Xen 3
ghsa_unreviewed·2022-05-17
CVE-2012-6333 [MEDIUM] GHSA-32g2-hc9h-69wc: Multiple HVM control operations in Xen 3
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
OSV
CVE-2012-6333: Multiple HVM control operations in Xen 3
osv·2012-12-13·CVSS 4.7
CVE-2012-6333 [MEDIUM] CVE-2012-6333: Multiple HVM control operations in Xen 3
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
Red Hat
kernel: xen: several HVM operations do not validate the range of their inputs
vendor_redhat·2012-12-03·CVSS 4.7
CVE-2012-6333 [MEDIUM] kernel: xen: several HVM operations do not validate the range of their inputs
kernel: xen: several HVM operations do not validate the range of their inputs
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-6333: xen - Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS ...
vendor_debian·2012·CVSS 4.7
CVE-2012-6333 [MEDIUM] CVE-2012-6333: xen - Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS ...
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
Scope: local
bookworm: resolved (fixed in 4.1.3-8)
bullseye: resolved (fixed in 4.1.3-8)
forky: resolved (fixed in 4.1.3-8)
sid: resolved (fixed in 4.1.3-8)
trixie: resolved (fixed in 4.1.3-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6333 kernel: xen: Several HVM operations do not validate the range of their inputs (a different vulnerability than CVE-2012-5511)
bugzilla·2012-12-13·CVSS 4.7
CVE-2012-6333 [MEDIUM] CVE-2012-6333 kernel: xen: Several HVM operations do not validate the range of their inputs (a different vulnerability than CVE-2012-5511)
CVE-2012-6333 kernel: xen: Several HVM operations do not validate the range of their inputs (a different vulnerability than CVE-2012-5511)
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6333 to the following vulnerability:
Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6333
[2] http://www.openwall.com/lists/oss-security/2012/12/03/10
[3] http://support.citrix.com/article/CTX135777
[4] http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.html
[5] http://www.securityfocus.com/bid/56796
[6] http://www.osvdb.org/88129
[7] http://secunia.com/advisories/51397
[8]
Bugzilla
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs [fedora-all]
bugzilla·2012-12-03·CVSS 4.7
CVE-2012-5511 [MEDIUM] CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs [fedora-all]
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field whe
Bugzilla
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs
bugzilla·2012-11-16·CVSS 4.7
CVE-2012-5511 [MEDIUM] CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs
CVE-2012-5511 CVE-2012-6333 kernel: xen: several HVM operations do not validate the range of their inputs
Several HVM control operations do not check the size of their inputs
and can tie up a physical CPU for extended periods of time.
In addition dirty video RAM tracking involves clearing the bitmap
provided by the domain controlling the guest (e.g. dom0 or a
stubdom). If the size of that bitmap is overly large, an intermediate
variable on the hypervisor stack may overflow that stack.
A malicious guest administrator can cause Xen to become unresponsive
or to crash leading in either case to a Denial of Service.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the
http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.openwall.com/lists/oss-security/2012/12/03/10http://www.osvdb.org/88129http://www.securityfocus.com/bid/56796https://exchange.xforce.ibmcloud.com/vulnerabilities/80484http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.openwall.com/lists/oss-security/2012/12/03/10http://www.osvdb.org/88129http://www.securityfocus.com/bid/56796https://exchange.xforce.ibmcloud.com/vulnerabilities/80484
2012-12-13
Published