First published: Fri Nov 23 2012(Updated: )
The do_tmem_get function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (CPU hang and host crash) via unspecified vectors related to a spinlock being held in the "bad_copy error path." NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.0.0 | |
Xen xen-unstable | =4.1.0 | |
Xen xen-unstable | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6031 has a high severity due to its potential to cause a denial of service resulting in CPU hang and host crash.
To mitigate CVE-2012-6031, upgrade your Xen installation to a version that is not affected, preferably above 4.2.0.
CVE-2012-6031 affects Xen versions 4.0.0, 4.1.0, and 4.2.0.
CVE-2012-6031 allows a local guest OS user to execute an attack that leads to a denial of service.
Yes, CVE-2012-6031 is considered a critical vulnerability due to its ability to affect system stability and availability.