CVE-2012-3498
EPSS 0.07%
Description
PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host crash) and possibly read hypervisor or guest memory via vectors related to a missing range check of map->index.
How to fix CVE-2012-3498
To remediate CVE-2012-3498, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.1.3-2 or later
Is CVE-2012-3498 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.1.3-2