The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-10-31 09:55
Updated : 2017-08-28 18:32
NVD link : CVE-2012-4544
Mitre link : CVE-2012-4544
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
xen
- xen