CVE-2012-5510

NameCVE-2012-5510
DescriptionXen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2582-1
NVD severitymedium (attack range: local)
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xen (PTS)squeeze (security), squeeze4.0.1-5.11fixed
wheezy4.1.4-3+deb7u3fixed
wheezy (security)4.1.4-3+deb7u4fixed
jessie4.4.1-6fixed
sid4.4.1-7fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xensource(unstable)4.1.3-5medium
xensourcesqueeze4.0.1-5.5mediumDSA-2582-1

Search for package or bug name: Reporting problems