CVE-2012-3496
published 2012-11-23CVE-2012-3496: XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.42%
33.9th percentile
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | <= 6.0.2 | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.1.3-2 (bookworm) | xen 4.1.3-2 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2012-3496: XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS
vendor_citrix·2012-11-23·CVSS 4.7
CVE-2012-3496 [MEDIUM] CWE-16 CVE-2012-3496: XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS
CVE-2012-3496: XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
Red Hat
kernel: xen: XENMEM_populate_physmap DoS vulnerability
vendor_redhat·2012-09-05·CVSS 4.7
CVE-2012-3496 [MEDIUM] kernel: xen: XENMEM_populate_physmap DoS vulnerability
kernel: xen: XENMEM_populate_physmap DoS vulnerability
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-3496: xen - XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and...
vendor_debian·2012·CVSS 4.7
CVE-2012-3496 [MEDIUM] CVE-2012-3496: xen - XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and...
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
Scope: local
bookworm: resolved (fixed in 4.1.3-2)
bullseye: resolved (fixed in 4.1.3-2)
forky: resolved (fixed in 4.1.3-2)
sid: resolved (fixed in 4.1.3-2)
trixie: resolved (fixed in 4.1.3-2)
Citrix
Citrix Security Bulletin CTX134708
vendor_citrix·CVSS 2.1
CVE-2012-3494 [LOW] Citrix Security Bulletin CTX134708
Citrix Security Bulletin CTX134708
CVE References: CVE-2012-3494, CVE-2012-3495, CVE-2012-3496, CVE-2012-3498, CVE-2012-3516, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-gw25-hcr4-7p5h: XENMEM_populate_physmap in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2012-3496 [MEDIUM] GHSA-gw25-hcr4-7p5h: XENMEM_populate_physmap in Xen 4
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
OSV
CVE-2012-3496: XENMEM_populate_physmap in Xen 4
osv·2012-11-23·CVSS 4.7
CVE-2012-3496 [MEDIUM] CVE-2012-3496: XENMEM_populate_physmap in Xen 4
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability [fedora-all]
bugzilla·2012-09-05·CVSS 4.7
CVE-2012-3496 [MEDIUM] CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability [fedora-all]
CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=se
Bugzilla
CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability
bugzilla·2012-08-23·CVSS 4.7
CVE-2012-3496 [MEDIUM] CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability
CVE-2012-3496 kernel: xen: XENMEM_populate_physmap DoS vulnerability
XENMEM_populate_physmap can be called with invalid flags. By calling it with MEMF_populate_on_demand flag set, a BUG can be triggered if a translating paging mode is not being used.
A malicious guest kernel can crash the host.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue. Upstream acknowledges Matthew Daley as the original reporter.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
---
Now public via:
http://seclists.org/oss-sec/2012/q3/378
---
C
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-09/msg00002.htmlhttp://secunia.com/advisories/50472http://secunia.com/advisories/50530http://secunia.com/advisories/51413http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://securitytracker.com/id?1027481http://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-14_XENMEM_populate_physmap_DoS_vulnerabilityhttp://www.debian.org/security/2012/dsa-2544http://www.openwall.com/lists/oss-security/2012/09/05/7http://www.osvdb.org/85200http://www.securityfocus.com/bid/55412https://bugzilla.redhat.com/show_bug.cgi?id=854590https://exchange.xforce.ibmcloud.com/vulnerabilities/78267https://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-09/msg00002.htmlhttp://secunia.com/advisories/50472http://secunia.com/advisories/50530http://secunia.com/advisories/51413http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://securitytracker.com/id?1027481http://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-14_XENMEM_populate_physmap_DoS_vulnerabilityhttp://www.debian.org/security/2012/dsa-2544http://www.openwall.com/lists/oss-security/2012/09/05/7http://www.osvdb.org/85200http://www.securityfocus.com/bid/55412https://bugzilla.redhat.com/show_bug.cgi?id=854590https://exchange.xforce.ibmcloud.com/vulnerabilities/78267https://security.gentoo.org/glsa/201604-03
2012-11-23
Published