The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk before or after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted kernel or ramdisk.