CVE-2012-3516
published 2012-11-23CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to…
PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.36%
27.9th percentile
The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | <= 6.0.2 | — |
| citrix | xenserver | — | — |
| debian | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrat
vendor_citrix·2012-11-23·CVSS 6.9
CVE-2012-3516 [MEDIUM] CWE-264 CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrat
CVE-2012-3516: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
Red Hat
kernel: xen: grant table entry swaps have inadequate bounds checking
vendor_redhat·2012-09-05·CVSS 6.9
CVE-2012-3516 [MEDIUM] CWE-863 kernel: xen: grant table entry swaps have inadequate bounds checking
kernel: xen: grant table entry swaps have inadequate bounds checking
The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-3516: xen - The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4....
vendor_debian·2012·CVSS 6.9
CVE-2012-3516 [MEDIUM] CVE-2012-3516: xen - The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4....
The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Citrix
Citrix Security Bulletin CTX134708
vendor_citrix·CVSS 2.1
CVE-2012-3494 [LOW] Citrix Security Bulletin CTX134708
Citrix Security Bulletin CTX134708
CVE References: CVE-2012-3494, CVE-2012-3495, CVE-2012-3496, CVE-2012-3498, CVE-2012-3516, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-rhpw-vvc9-379j: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2012-3516 [MEDIUM] GHSA-rhpw-vvc9-379j: The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4
The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking [fedora-all]
bugzilla·2012-09-05·CVSS 6.9
CVE-2012-3516 [MEDIUM] CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking [fedora-all]
CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates
Bugzilla
CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking
bugzilla·2012-08-23·CVSS 6.9
CVE-2012-3516 [MEDIUM] CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking
CVE-2012-3516 kernel: xen: grant table entry swaps have inadequate bounds checking
The grant table hypercall's GNTTABOP_swap_grant_ref sub-operation does not perform adequate checks on the input grant references.
A malicious guest kernel or administrator can crash the host.
It may be possible for an attacker to swap a valid grant reference, which they control, with an invalid one allowing them to write abitrary values to hypervisor memory. This could potentially lead to a
privilege escalation.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 an
Bugzilla
CVE-2011-3516 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)
bugzilla·2011-10-19·CVSS 7.6
CVE-2011-3516 [HIGH] CVE-2011-3516 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)
CVE-2011-3516 Oracle/IBM JDK: unspecified vulnerability fixed in 6u29 (Deployment)
Update 29 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2011-3516). Upstream has CVSSv2 scored this issue as: 5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Extras for RHEL 4
Via RHSA-2011:1384 https://rhn.redhat.com/errata/RHSA-2011-1384.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Extras for RHEL 4
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://secunia.com/advisories/50472http://secunia.com/advisories/50530http://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-18_grant_table_entry_swaps_have_inadequate_bounds_checkinghttp://www.openwall.com/lists/oss-security/2012/09/05/11http://www.securityfocus.com/bid/55411http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.htmlhttp://secunia.com/advisories/50472http://secunia.com/advisories/50530http://support.citrix.com/article/CTX134708http://wiki.xen.org/wiki/Security_Announcements#XSA-18_grant_table_entry_swaps_have_inadequate_bounds_checkinghttp://www.openwall.com/lists/oss-security/2012/09/05/11http://www.securityfocus.com/bid/55411
2012-11-23
Published