CVE-2012-6036

Source
https://cve.org/CVERecord?id=CVE-2012-6036
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-6036.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-6036
Downstream
Published
2012-11-23T20:55:04Z
Modified
2026-04-10T03:42:32.974881Z
Summary
[none]
Details

The (1) memcsavegetnextpage, (2) tmemcrestoreputpage and (3) tmemcrestoreflushpage functions in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 do not check for negative id pools, which allows local guest OS users to cause a denial of service (memory corruption and host crash) or possibly execute arbitrary code via unspecified vectors. NOTE: this issue was originally published as part of CVE-2012-3497, which was too general; CVE-2012-3497 has been SPLIT into this ID and others.

References

Affected packages