CVE-2012-6036: Medium severity xen xapi vulnerability
The (1) memcsavegetnextpage, (2) tmemcrestoreputpage and (3) tmemcrestoreflushpage functions in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 do not check for negative id pools, which allows local guest OS users to cause a denial of service (memory corruption and host crash) or possibly execute arbitrary code via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6036?
CVE-2012-6036 has a medium severity rating due to its potential to cause denial of service by allowing memory corruption and host crashes.
How do I fix CVE-2012-6036?
To fix CVE-2012-6036, upgrade to a patched version of Xen, specifically versions beyond 4.2.0 that address this vulnerability.
Which versions of Xen are affected by CVE-2012-6036?
CVE-2012-6036 affects Xen versions 4.0.0, 4.1.0, and 4.2.0.
What type of attacks can exploit CVE-2012-6036?
CVE-2012-6036 can be exploited by local guest OS users to trigger denial of service attacks.
Is there a workaround for CVE-2012-6036?
There are no known workarounds for CVE-2012-6036; upgrading to a secure version is the recommended action.