Back to search
CVE-2012-6035
Published: Nov 23, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly validate pool ids, which allows local guest OS users to cause a denial of service (memory corruption and host crash) or execute arbitrary code via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
55082
third-party-advisory
x_refsource_SECUNIA
1027482
vdb-entry
x_refsource_SECTRACK
GLSA-201309-24
vendor-advisory
x_refsource_GENTOO
55410
vdb-entry
x_refsource_BID
[oss-security] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities
mailing-list
x_refsource_MLIST
xen-tmem-priv-esc(78268)
vdb-entry
x_refsource_XF
85199
vdb-entry
x_refsource_OSVDB
[Xen-announce] 20120905 Xen Security Advisory 15 (CVE-2012-3497) - multiple TMEM hypercall vulnerabilities
mailing-list
x_refsource_MLIST
50472
third-party-advisory
x_refsource_SECUNIA
GLSA-201604-03
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now