Resource management error in Xen - CVE-2011-3262

 

Resource management error in Xen - CVE-2011-3262

Published: August 19, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU44799
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3262
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."


Affected software

Xen
Gentoo Linux
app-emulation/xen
app-emulation/xen-pvgrub
app-emulation/xen-tools

How to mitigate CVE-2011-3262

Install update from vendor's website.

app-emulation/xen - update to 4.2.2-r1
app-emulation/xen-pvgrub - update to 4.2.2-r1
app-emulation/xen-tools - update to 4.2.2-r3

External References

Related Security Bulletins