CVE-2012-3498
published 2012-11-23CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and…
PriorityP418medium5.6CVSS 2.0
AVLACLAuNCPINAC
EPSS
0.44%
35.4th percentile
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | <= 6.0.2 | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.1.3-2 (bookworm) | xen 4.1.3-2 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
| xen | xen | >= 0 < 4.1.3-2 | 4.1.3-2 |
CVSS provenance
nvdv2.05.6MEDIUMAV:L/AC:L/Au:N/C:P/I:N/A:C
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host cras
vendor_citrix·2012-11-23·CVSS 5.6
CVE-2012-3498 [MEDIUM] CWE-20 CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host cras
CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
Red Hat
kernel: xen: PHYSDEVOP_map_pirq index vulnerability
vendor_redhat·2012-09-05·CVSS 5.6
CVE-2012-3498 [MEDIUM] kernel: xen: PHYSDEVOP_map_pirq index vulnerability
kernel: xen: PHYSDEVOP_map_pirq index vulnerability
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-3498: xen - PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier all...
vendor_debian·2012·CVSS 5.6
CVE-2012-3498 [MEDIUM] CVE-2012-3498: xen - PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier all...
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
Scope: local
bookworm: resolved (fixed in 4.1.3-2)
bullseye: resolved (fixed in 4.1.3-2)
forky: resolved (fixed in 4.1.3-2)
sid: resolved (fixed in 4.1.3-2)
trixie: resolved (fixed in 4.1.3-2)
Citrix
Citrix Security Bulletin CTX134708
vendor_citrix·CVSS 2.1
CVE-2012-3494 [LOW] Citrix Security Bulletin CTX134708
Citrix Security Bulletin CTX134708
CVE References: CVE-2012-3494, CVE-2012-3495, CVE-2012-3496, CVE-2012-3498, CVE-2012-3516, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-2gjh-pw8m-qmpj: PHYSDEVOP_map_pirq in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2012-3498 [MEDIUM] CWE-20 GHSA-2gjh-pw8m-qmpj: PHYSDEVOP_map_pirq in Xen 4
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
OSV
CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4
osv·2012-11-23·CVSS 5.6
CVE-2012-3498 [MEDIUM] CVE-2012-3498: PHYSDEVOP_map_pirq in Xen 4
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3498 kernel: xen: PHYSDEVOP_map_pirq index vulnerability [fedora-all]
bugzilla·2012-09-05·CVSS 5.6
CVE-2012-3498 [MEDIUM] CVE-2012-3498 kernel: xen: PHYSDEVOP_map_pirq index vulnerability [fedora-all]
CVE-2012-3498 kernel: xen: PHYSDEVOP_map_pirq index vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=secur
Bugzilla
CVE-2012-3498 kernel: xen: PHYSDEVOP_map_pirq index vulnerability
bugzilla·2012-08-23·CVSS 5.6
CVE-2012-3498 [MEDIUM] CVE-2012-3498 kernel: xen: PHYSDEVOP_map_pirq index vulnerability
CVE-2012-3498 kernel: xen: PHYSDEVOP_map_pirq index vulnerability
PHYSDEVOP_map_pirq with MAP_PIRQ_TYPE_GSI does not range check map->index.
A malicious HVM guest kernel can crash the host. It might also be able to read hypervisor or guest memory.
All Xen systems running HVM guests are vulnerable. PV guests are not vulnerable.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue. Upstream acknowledges Matthew Daley as the original reporter.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
---
Now public via:
http://seclis
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-09/msg00005.htmlhttp://osvdb.org/85198http://secunia.com/advisories/50472http://secunia.com/advisories/50530http://secunia.com/advisories/51413http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://securitytracker.com/id?1027483http://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-16_PHYSDEVOP_map_pirq_index_vulnerabilityhttp://www.openwall.com/lists/oss-security/2012/09/05/9http://www.securityfocus.com/bid/55414https://bugzilla.redhat.com/show_bug.cgi?id=851193https://exchange.xforce.ibmcloud.com/vulnerabilities/78269https://security.gentoo.org/glsa/201604-03http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.htmlhttp://lists.xen.org/archives/html/xen-announce/2012-09/msg00005.htmlhttp://osvdb.org/85198http://secunia.com/advisories/50472http://secunia.com/advisories/50530http://secunia.com/advisories/51413http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://securitytracker.com/id?1027483http://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-16_PHYSDEVOP_map_pirq_index_vulnerabilityhttp://www.openwall.com/lists/oss-security/2012/09/05/9http://www.securityfocus.com/bid/55414https://bugzilla.redhat.com/show_bug.cgi?id=851193https://exchange.xforce.ibmcloud.com/vulnerabilities/78269https://security.gentoo.org/glsa/201604-03
2012-11-23
Published