The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2012-10-31T16:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2012-08-21T00:00:00
Link: CVE-2012-4544
JSON object: View
NVD Information
Status : Modified
Published: 2012-10-31T16:55:05.827
Modified: 2017-08-29T01:32:18.853
Link: CVE-2012-4544
JSON object: View
Redhat Information
No data.
CWE