The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administrators to cause a denial of service (host crash) and possibly gain privileges via a crafted grant reference that triggers a write to an arbitrary hypervisor memory location.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/55411 | vdb entry |
http://secunia.com/advisories/50530 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2012/09/05/11 | mailing list |
http://secunia.com/advisories/50472 | third party advisory vendor advisory |
http://support.citrix.com/article/CTX134708 | patch vendor advisory |
http://wiki.xen.org/wiki/Security_Announcements#XSA-18_grant_table_entry_swaps_have_inadequate_bounds_checking | |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html | vendor advisory |