English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Xen HVM Guest MMIO Emulation Denial of Service Vulnerability


Secunia ID

SA49789

CVE-ID

CVE-2012-3432

Release Date

27 Jul 2012

Last Change

30 Jul 2012

Criticality

Not Critical

Solution Status

Vendor Patch

Software

Xen 4.x

Where

Local system

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in Xen, which can be exploited by malicious, local users in a guest virtual machine to cause a DoS (Denial of Service).

The vulnerability is caused due to certain data of MMIO operations not being handled properly after emulation cycles in HVM guests and can be exploited to crash subsequent emulations.

Successful exploitation requires that the guests are not PV (para-virtualised).

The vulnerability is reported in all supported versions.

Solution

Apply patch xsa10-4.x.patch.

Reported by

Reported by the vendor.

Original Advisory

http://lists.xen.org/archives/html/xen-devel/2012-07/msg01649.html