CVE-2012-3495: Input Validation
The physdevgetfreepirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the getfreepirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain privileges via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3495?
CVE-2012-3495 has a medium severity rating as it can lead to a denial of service.
How do I fix CVE-2012-3495?
To mitigate CVE-2012-3495, upgrade Xen to version 4.1.4 or higher and ensure Citrix XenServer is updated beyond version 6.0.2.
Which versions are affected by CVE-2012-3495?
CVE-2012-3495 affects Xen version 4.1.x and Citrix XenServer versions 5.0, 5.5, 5.6, and 6.0.2 and earlier.
What type of vulnerability is CVE-2012-3495?
CVE-2012-3495 is a software vulnerability that allows a guest OS user to cause a denial of service.
Is CVE-2012-3495 a remote vulnerability?
CVE-2012-3495 can be exploited locally by malicious guest OS users to affect system availability.