CVE-2012-4544

low
Published 2012-10-31 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4544

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/51071

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.1.3-4
debian debianbullseyefixed4.1.3-4
debian debianforkyfixed4.1.3-4
debian debiansidfixed4.1.3-4
debian debiantrixiefixed4.1.3-4

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.