Release date: 2012-4 4
Updated on: 2012-12-07
Affected Systems:
XenSource Xen 4.x
XenSource Xen 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56798
CVE (CAN) ID: CVE-2012-5515
Xen is an open-source Virtual Machine monitor developed by the University of Cambridge.
Xen has an error in processing the extent_order Value of "XENMEM_decrease_reservation", "XENMEM_populate_physmap", and "XENMEM_exchange", which can be exploited to cause suspension.
<* Source: vendor
Link: http://secunia.com/advisories/51397/
Http://lists.xen.org/archives/html/xen-announce/2012-12/msg00001.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XenSource
---------
The vendor has released a patch to fix this security problem. Please download the patch from the vendor's homepage.
Xsa31-4.1.patch Xen 4.1.x
Xsa31-4.2-unstable.patch Xen 4.2.x, xen-unstable
Http://xen.xensource.com/