CVE-2012-5515: Medium severity xen xapi vulnerability
The (1) XENMEMdecreasereservation, (2) XENMEMpopulatephysmap, and (3) XENMEMexchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extentorder value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5515?
CVE-2012-5515 is classified as a denial of service vulnerability due to its potential to cause system hangs.
How do I fix CVE-2012-5515?
The recommended solution to mitigate CVE-2012-5515 is to upgrade to a version of Xen later than 4.2.
Which versions of Xen are affected by CVE-2012-5515?
CVE-2012-5515 affects Xen versions 4.2 and earlier, including specific releases from 3.0.2 to 4.2.0.
Can a local guest administrator exploit CVE-2012-5515?
Yes, local guest administrators can exploit CVE-2012-5515 by crafting specific values that lead to prolonged resource loops.
Is there a workaround for CVE-2012-5515?
While upgrading is the best approach, administrators can limit access for guest administrators to mitigate potential exploitation.