CVE-2012-3433
EPSS 0.07%
Description
Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.
How to fix CVE-2012-3433
To remediate CVE-2012-3433, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.1.3-1 or later
Is CVE-2012-3433 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.3-1