← Vulnerability feed

Vulnerability record · CVE-2012-3494 · published 23 November 2012

CVE-2012-3494: Citrix xenserver permissions and access controls vulnerability

Citrix · Xenserver

The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.

2.1 CVSS 2.0 Low EPSS 0.44% · top 64.3% CWE-264 · Permissions and access controls
2.1CVSS 2.0 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
50References
16 Jun 2026Last modified by NVD

Description

The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of the DR7 debug control register.

AV:L/AC:L/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
http://lists.xen.org/archives/html/xen-announce/2012-09/msg00000.html
http://osvdb.org/85197
http://secunia.com/advisories/50472 Vendor Advisory
http://secunia.com/advisories/50530 Vendor Advisory
http://secunia.com/advisories/51413
http://secunia.com/advisories/55082
http://security.gentoo.org/glsa/glsa-201309-24.xml
http://support.citrix.com/article/CTX134708 PatchVendor Advisory
http://wiki.xen.org/wiki/Security_Announcements#XSA-12_hypercall_set_debugreg_vulnerability
http://www.debian.org/security/2012/dsa-2544
http://www.openwall.com/lists/oss-security/2012/09/05/5
http://www.securityfocus.com/bid/55400
http://www.securitytracker.com/id?1027479
https://bugzilla.redhat.com/show_bug.cgi?id=851139
https://exchange.xforce.ibmcloud.com/vulnerabilities/78265
https://security.gentoo.org/glsa/201604-03
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00018.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
http://lists.xen.org/archives/html/xen-announce/2012-09/msg00000.html
http://osvdb.org/85197
http://secunia.com/advisories/50472 Vendor Advisory
http://secunia.com/advisories/50530 Vendor Advisory
http://secunia.com/advisories/51413
http://secunia.com/advisories/55082

Track CVE-2012-3494 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-10920Xen memory buffer overflow vulnerabilityThe grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unma…EPSS 2.5%10.0CVE-2017-10918Xen improper input validation vulnerabilityXen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access…EPSS 3.7%10.0CVE-2017-10921Xen memory buffer overflow vulnerabilityThe grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows…EPSS 2.5%10.0CVE-2017-10912Xen vulnerabilityXen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.EPSS 2.7%10.0CVE-2015-8104Xen vulnerabilityThe KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic o…EPSS 2.5%10.0CVE-2014-4947Citrix xenserver memory buffer overflow vulnerabilityBuffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.EPSS 5.4%9.9CVE-2016-9603Qemu heap-based buffer overflow vulnerabilityA heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a V…EPSS 4.4%9.9CVE-2017-2620Qemu out-of-bounds write vulnerabilityQuick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2012-3494), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.