CVE-2012-5510

Xen 4.x - Denial of Service via Grant Table Version Downgrade

Title source: llm
STIX 2.1

Description

Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

References (19)

Core 19
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/12/03/6
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55082
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-04/msg00052.html
Vendor Advisory x_refsource_confirm
http://support.citrix.com/article/CTX135777
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201309-24.xml
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2582
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51397
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51486
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51487
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56794
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51468
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-04/msg00051.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/88128
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80478

Scores

EPSS 0.0009
EPSS Percentile 25.7%

Details

Status published
Products (10)
xen/xen 4.0.0
xen/xen 4.0.1
xen/xen 4.0.2
xen/xen 4.0.3
xen/xen 4.0.4
xen/xen 4.1.0
xen/xen 4.1.1
xen/xen 4.1.2
xen/xen 4.1.3
xen/xen 4.2.0
Published Dec 13, 2012
Tracked Since Feb 18, 2026