CVE-2012-2625

low
Published 2012-10-31 · Modified 2026-04-29
CVSS v3
CVSS v2
2.7
VIR risk
2.7

Description

The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2625

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://xenbits.xensource.com/hg/xen-unstable.hg/rev/60f09d1ab1fe

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.1.3-4
debian debianbullseyefixed4.1.3-4
debian debianforkyfixed4.1.3-4
debian debiansidfixed4.1.3-4
debian debiantrixiefixed4.1.3-4

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.