CVE-2011-3262 is a denial-of-service vulnerability in Xen versions 3.2, 3.3, 4.0, and 4.1, specifically within the xc_dom_bzimageloader.c component, affecting Citrix Xen products. A local attacker can exploit a lack of error checking in the decompression loop to trigger an infinite loop in management software, leading to resource exhaustion in the management domain. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P), indicating local access, low attack complexity, and a partial availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.0CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.2.0:*:*:*:*:*:*:* | ||
3.3.0CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.3.0:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:citrix:xen:4.0.0:*:*:*:*:*:*:* | ||
4.1.0CPE matchmatch criteria | cpe:2.3:a:citrix:xen:4.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.