CVE-2012-6033
EPSS 0.07%
Description
The do_tmem_control function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly check privileges, which allows local guest OS users to access control stack operations via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.
How to fix CVE-2012-6033
To remediate CVE-2012-6033, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.1.4-1 or later
Is CVE-2012-6033 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.4-1