CVE-2012-6031: Input Validation
The dotmemget function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (CPU hang and host crash) via unspecified vectors related to a spinlock being held in the "badcopy error path." NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6031?
CVE-2012-6031 has a high severity due to its potential to cause a denial of service resulting in CPU hang and host crash.
How do I fix CVE-2012-6031?
To mitigate CVE-2012-6031, upgrade your Xen installation to a version that is not affected, preferably above 4.2.0.
Which versions of Xen are affected by CVE-2012-6031?
CVE-2012-6031 affects Xen versions 4.0.0, 4.1.0, and 4.2.0.
What type of attack does CVE-2012-6031 enable?
CVE-2012-6031 allows a local guest OS user to execute an attack that leads to a denial of service.
Is CVE-2012-6031 a critical vulnerability?
Yes, CVE-2012-6031 is considered a critical vulnerability due to its ability to affect system stability and availability.