First published: Thu Aug 23 2012(Updated: )
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
XenServer | <=6.0.2 | |
Xen xen-unstable | =4.1.0 | |
Xen xen-unstable | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3498 is rated as a critical vulnerability due to its potential to cause host crashes and unauthorized access to sensitive memory.
To fix CVE-2012-3498, you should upgrade to Xen versions 4.3 or later, or Citrix XenServer version 6.1 or newer.
CVE-2012-3498 affects local HVM guest OS kernels running on Xen 4.1, 4.2, and Citrix XenServer versions up to and including 6.0.2.
CVE-2012-3498 is a denial of service vulnerability that can lead to a host crash and possible memory exposure.
Exploiting CVE-2012-3498 can result in severe disruption of the host system and potential exposure of hypervisor or guest memory.