CVE-2012-3432
Summary
| CVE | CVE-2012-3432 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-03 21:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial of service (guest OS crash) via unspecified operations on MMIO regions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:L/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Xen | Xen | 3.3.0 | All | All | All |
| Operating System | Xen | Xen | 4.0.0 | All | All | All |
| Operating System | Xen | Xen | 4.0.1 | All | All | All |
| Operating System | Xen | Xen | 4.0.2 | All | All | All |
| Operating System | Xen | Xen | 4.0.3 | All | All | All |
| Operating System | Xen | Xen | 4.0.4 | All | All | All |
| Operating System | Xen | Xen | 4.1.0 | All | All | All |
| Operating System | Xen | Xen | 4.1.1 | All | All | All |
| Operating System | Xen | Xen | 4.1.2 | All | All | All |
| Operating System | Xen | Xen | 4.1.3 | All | All | All |
| Operating System | Xen | Xen | 4.2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Linux Documentation -- Xen: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [security-announce] SUSE-SU-2012:1044-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Xen HVM Guest User Mode MMIO Emulation Local Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] openSUSE-SU-2012:1172-1: important: Security Update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] SUSE-SU-2012:1043-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2012:1174-1: important: Security Update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2531-1 xen | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA55082 - Gentoo update for xen - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [Xen-devel] Xen Security Advisory 10 (CVE-2012-3432) - HVM user mode MMIO emul DoS | af854a3a-2127-422b-91ae-364da2661108 | lists.xen.org | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.