CVE-2012-3516Incorrect Authorization in Citrix Xenserver

Severity
6.9MEDIUMNVD
EPSS
0.1%
top 76.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 23
Latest updateMay 17

Description

The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

NVDcitrix/xenserver6.0.2
NVDxen/xen4.2.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rhpw-vvc9-379j: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 42022-05-17
CVEList
CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 42012-11-23

📋Vendor Advisories

3
Citrix
CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrat2012-11-23
Red Hat
kernel: xen: grant table entry swaps have inadequate bounds checking2012-09-05
Debian
CVE-2012-3516: xen - The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4....2012

💬Community

3
Bugzilla
CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking [fedora-all]2012-09-05
Bugzilla
CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking2012-08-23
Bugzilla
CVE-2011-3516 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)2011-10-19
CVE-2012-3516 — Incorrect Authorization in Citrix | cvebase