CVE-2012-0218: Xen

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.

Affected products

  • Xen Xen: version 3.4.0 only; version 4.0.0 only; version 4.1.0 only

Published 2012-12-03. Last modified 2026-06-16.