VDB

DEBIAN-CVE-2012-4544

DEBIAN-CVE-2012-4544 PUBLISHED CVSS 6.900000095367432 MEDIUM

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

Risk Scores

CVSS v4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:12xen0, 0, 0
Debian:14xen0, 0, 0
Debian:13xen0, 0, 0
Debian:11xen0, 0, 0

Timeline

  • Oct 31, 2012 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›