Resource management error in Xen - CVE-2011-3262
Published: August 19, 2011 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."
Affected software
Gentoo Linux
app-emulation/xen
app-emulation/xen-pvgrub
app-emulation/xen-tools
How to mitigate CVE-2011-3262
app-emulation/xen-pvgrub - update to 4.2.2-r1
app-emulation/xen-tools - update to 4.2.2-r3