Back

LOW

xen: Xen domain builder Out-of-memory due to malicious kernel/ramdisk

Published Oct 31, 2012

Description

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 31, 2012
Updated Aug 6, 2024
Reserved Aug 21, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Oct 26, 2012