Denial of Service and Potential Privilege Escalation in Xen and Citrix XenServer
CVE-2012-3516
Currently unrated
Summary
A flaw in the GNTTABOP_swap_grant_ref operation within the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 could allow local guest kernels or system administrators to induce a denial of service by executing a crafted grant reference, potentially leading to host crashes. This vulnerability has implications for security as it may also enable privilege escalation by allowing unauthorized write access to arbitrary hypervisor memory locations.
References
Timeline
Vulnerability published
Vulnerability Reserved