CVE-2012-3433: Medium severity XEN Xen vulnerability
Published Nov 24, 2012
·Updated
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
Affected Software
2 affected components
XEN Xen=4.0.0
XEN Xen=4.1.0
Event History
Nov 24, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3433?
CVE-2012-3433 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2012-3433?
To fix CVE-2012-3433, upgrade to Xen version 4.2 or later, which addresses this vulnerability.
3
What types of systems are affected by CVE-2012-3433?
CVE-2012-3433 affects local HVM guest OS kernels running on Xen versions 4.0 and 4.1.
4
What is the impact of exploiting CVE-2012-3433?
Exploiting CVE-2012-3433 can lead to domain 0 VCPU hang and kernel panic, resulting in disruption of services.
5
Is there a known workaround for CVE-2012-3433?
There is no reliable workaround for CVE-2012-3433; upgrading to a patched version is recommended.