CVE-2012-3496
EPSS 0.09%
Description
XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode is not used, allows local PV OS guest kernels to cause a denial of service (BUG triggered and host crash) via invalid flags such as MEMF_populate_on_demand.
How to fix CVE-2012-3496
To remediate CVE-2012-3496, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.1.3-2 or later
Is CVE-2012-3496 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.3-2