CVE-2012-0218
EPSS 0.07%
Description
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.
How to fix CVE-2012-0218
To remediate CVE-2012-0218, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1 or later
Is CVE-2012-0218 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.3~rc1+hg-20120614.a9c0a89c08f2-1