« List of all CVEs

CVE-2011-1583

Published: 8/12/2011 Last updated: 8/6/2024 Reserved: 4/5/2011

Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overflow during a decompression loop or (2) an out-of-bounds read in the loader involving unspecified length fields.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-xen xen-evtchn

Products affected (1)

Product Vendor Version
n/a n/a 24.0 ap385259

References (6)