CVE-2012-4538: Input Validation
Published Nov 24, 2012
·Updated
The HVMOPpagetabledying hypercall in Xen 4.0, 4.1, and 4.2 does not properly check the pagetable state when running on shadow pagetables, which allows a local HVM guest OS to cause a denial of service (hypervisor crash) via unspecified vectors.
Affected Software
3 affected components
XEN Xen=4.0.0
XEN Xen=4.1.0
XEN Xen=4.2.0
Event History
Nov 24, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4538?
CVE-2012-4538 has been classified as a denial of service vulnerability that can crash the hypervisor.
2
How do I fix CVE-2012-4538?
To remediate CVE-2012-4538, upgrade to a patched version of Xen beyond 4.2.
3
Who is affected by CVE-2012-4538?
CVE-2012-4538 affects local HVM guest operating systems running on Xen versions 4.0, 4.1, and 4.2.
4
What impact does CVE-2012-4538 have on my system?
CVE-2012-4538 can lead to hypervisor crashes resulting in service disruptions for virtual machines.
5
Is CVE-2012-4538 exploitable remotely?
CVE-2012-4538 is not a remote vulnerability; it requires local access to the HVM guest OS to be exploited.