Candidate: CVE-2012-4537 PublicDate: 2012-11-21 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4537 http://xforce.iss.net/xforce/xfdb/80024 http://www.securitytracker.com/id?1027761 http://www.openwall.com/lists/oss-security/2012/11/13/6 http://osvdb.org/87307 http://lists.xen.org/archives/html/xen-announce/2012-11/msg00005.html Description: Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability." Ubuntu-Description: Notes: kees> for full-virtualization issues, add qemu (and kvm) Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_xen-3.1: Tags_xen-3.1: universe-binary upstream_xen-3.1: needs-triage hardy_xen-3.1: ignored (reached end-of-life) lucid_xen-3.1: DNE oneiric_xen-3.1: DNE precise_xen-3.1: DNE quantal_xen-3.1: DNE raring_xen-3.1: DNE saucy_xen-3.1: DNE devel_xen-3.1: DNE Patches_xen-3.2: Tags_xen-3.2: universe-binary upstream_xen-3.2: needs-triage hardy_xen-3.2: ignored (reached end-of-life) lucid_xen-3.2: DNE oneiric_xen-3.2: DNE precise_xen-3.2: DNE quantal_xen-3.2: DNE raring_xen-3.2: DNE saucy_xen-3.2: DNE devel_xen-3.2: DNE Patches_xen-3.3: Tags_xen-3.3: universe-binary upstream_xen-3.3: needs-triage hardy_xen-3.3: DNE lucid_xen-3.3: ignored (reached end-of-life) oneiric_xen-3.3: DNE precise_xen-3.3: DNE quantal_xen-3.3: DNE raring_xen-3.3: DNE saucy_xen-3.3: DNE devel_xen-3.3: DNE Patches_xen: Tags_xen: universe-binary upstream_xen: needs-triage hardy_xen: DNE lucid_xen: DNE oneiric_xen: released (4.1.1-2ubuntu4.3) precise_xen: released (4.1.2-2ubuntu2.3) quantal_xen: released (4.1.3-3ubuntu1.1) raring_xen: released (4.2.0-1ubuntu2) saucy_xen: released (4.2.0-1ubuntu2) devel_xen: released (4.2.0-1ubuntu2)