SB2012100128 - Permissions, Privileges, and Access Controls in xen (Alpine package)



SB2012100128 - Permissions, Privileges, and Access Controls in xen (Alpine package)

Published: October 1, 2012

Security Bulletin ID SB2012100128
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-3432)

The vulnerability allows a local non-authenticated attacker to perform service disruption.

The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions.


Remediation

Install update from vendor's website.