CVE-2012-4544: Xen
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.
Affected products
- Xen Xen: up to and including 4.2.0; version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.1.3 only
Published 2012-10-31. Last modified 2026-06-16.