CVE-2012-5512
published 2012-12-13CVE-2012-5512: Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain…
PriorityP48low3.2CVSS 2.0
AVLACLAuSCPINAP
EPSS
0.41%
32.9th percentile
Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.1.3-5 (bookworm) | xen 4.1.3-5 (bookworm) |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
| xen | xen | >= 0 < 4.1.3-5 | 4.1.3-5 |
CVSS provenance
nvdv2.03.2LOWAV:L/AC:L/Au:S/C:P/I:N/A:P
osv3.2LOW
vendor_debian3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2ccw-9fqf-xvp4: Array index error in the HVMOP_set_mem_access handler in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2012-5512 [LOW] GHSA-2ccw-9fqf-xvp4: Array index error in the HVMOP_set_mem_access handler in Xen 4
Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
OSV
CVE-2012-5512: Array index error in the HVMOP_set_mem_access handler in Xen 4
osv·2012-12-13·CVSS 3.2
CVE-2012-5512 [LOW] CVE-2012-5512: Array index error in the HVMOP_set_mem_access handler in Xen 4
Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
Red Hat
kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak
vendor_redhat·2012-12-03·CVSS 3.2
CVE-2012-5512 [LOW] kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak
kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak
Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-5512: xen - Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HV...
vendor_debian·2012·CVSS 3.2
CVE-2012-5512 [LOW] CVE-2012-5512: xen - Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HV...
Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.1.3-5)
bullseye: resolved (fixed in 4.1.3-5)
forky: resolved (fixed in 4.1.3-5)
sid: resolved (fixed in 4.1.3-5)
trixie: resolved (fixed in 4.1.3-5)
Citrix
Citrix Security Bulletin CTX135777
vendor_citrix·CVSS 3.2
CVE-2012-5512 [LOW] Citrix Security Bulletin CTX135777
Citrix Security Bulletin CTX135777
CVE References: CVE-2012-5512, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5512 kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak [fedora-all]
bugzilla·2012-12-03·CVSS 3.2
CVE-2012-5512 [LOW] CVE-2012-5512 kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak [fedora-all]
CVE-2012-5512 kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2012-5512 kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak
bugzilla·2012-11-16·CVSS 3.2
CVE-2012-5512 [LOW] CVE-2012-5512 kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak
CVE-2012-5512 kernel: xen: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak
The HVMOP_set_mem_access operation handler uses an input as an array index before range checking it.
A malicious HVM guest administrator can cause Xen to crash. If the out of array bounds access does not crash, the arbitrary value read will be used if the caller reads back the default access through the HVMOP_get_mem_access operation, thus causing an information leak. The caller cannot, however, directly control the address from which to read, since the value read in the first step will be used as an array index again in the second step.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect
http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00011.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.openwall.com/lists/oss-security/2012/12/03/7http://www.osvdb.org/88132http://www.securityfocus.com/bid/56799https://exchange.xforce.ibmcloud.com/vulnerabilities/80481http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00011.htmlhttp://secunia.com/advisories/51397http://secunia.com/advisories/51486http://secunia.com/advisories/51487http://secunia.com/advisories/55082http://security.gentoo.org/glsa/glsa-201309-24.xmlhttp://support.citrix.com/article/CTX135777http://www.openwall.com/lists/oss-security/2012/12/03/7http://www.osvdb.org/88132http://www.securityfocus.com/bid/56799https://exchange.xforce.ibmcloud.com/vulnerabilities/80481
2012-12-13
Published