LOW
kernel: xen: VCPU timer overflow leads to PCPU deadlock and host death-by-watchdog
Published Nov 21, 2012
1.9
LOWCVSS 2.0
EPSS 0.40%
Description
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-308.24.1.el5
Fixed · RHSA-2012:1540
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-308.24.1.el5 | Fixed | RHSA-2012:1540 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5. This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Weaknesses (1)
References (27)
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.html vendor-advisoryx_refsource_SUSE
- http://lists.xen.org/archives/html/xen-announce/2012-11/msg00001.html mailing-listx_refsource_MLISTVendor Advisory
- http://osvdb.org/87298 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2012-1540.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/51200 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/51324 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/51352 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/51413 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/51468 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/55082 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201309-24.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2012/dsa-2582 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2012/11/13/1 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/56498 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1027759 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2012-4535 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=870086 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80022 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2012-4535
- https://security.gentoo.org/glsa/201604-03 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2012-4535
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 21, 2012
Updated Aug 6, 2024
Reserved Aug 21, 2012
Link CVE-2012-4535
CISA Vulnrichment
Updated n/a