Denial of Service and Potential Privilege Escalation in Xen and Citrix XenServer
CVE-2012-3516

Currently unrated

Key Information:

Vendor
Citrix
Vendor
CVE Published:
23 November 2012

Summary

A flaw in the GNTTABOP_swap_grant_ref operation within the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 could allow local guest kernels or system administrators to induce a denial of service by executing a crafted grant reference, potentially leading to host crashes. This vulnerability has implications for security as it may also enable privilege escalation by allowing unauthorized write access to arbitrary hypervisor memory locations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.