kernel: x86-64: avoid sysret to non-canonical address
Published Jun 12, 2012
7.2
HIGHCVSS 2.0
EPSS 39.84%
Description
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.
Affected products
No data.
Configuration 4
Configuration 5
- n/a
- n/a
- n/a
- r2
- n/a
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-308.8.2.el5
Fixed · RHSA-2012:0721
Red Hat Enterprise Linux 5.6 EUS - Server Only
kernel-0:2.6.18-238.39.1.el5
Fixed · RHSA-2012:0720
Red Hat Enterprise Linux 5
kernel-xen
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise MRG 2
realtime-kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-308.8.2.el5 | Fixed | RHSA-2012:0721 |
| Red Hat Enterprise Linux 5.6 EUS - Server Only | kernel-0:2.6.18-238.39.1.el5 | Fixed | RHSA-2012:0720 |
| Red Hat Enterprise Linux 5 | kernel-xen | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise MRG 2 | realtime-kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and 6, and Red Hat Enterprise MRG, as those versions have a guard page between the end of the user-mode accessible virtual address space and the beginning of the non-canonical area due to CVE-2005-1764 fix, and hardened system call handler due to CVE-2006-0744 fix. This issue did affect the versions of Xen hypervisor as shipped with Red Hat Enterprise Linux 5. A kernel-xen update for Red Hat Enterprise Linux 5 is available to address this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 39.84% (0.39835) | 98.58th | v5 (v2026.06.15) |
| Sep 8, 2026 | 39.84% (0.39835) | 98.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 37.46% (0.37465) | 98.33th | v5 (v2026.06.15) |
| Dec 27, 2025 | 88.72% (0.88722) | 99.49th | v4 (v2025.03.14) |
| Aug 12, 2025 | 87.41% (0.87414) | 99.41th | v4 (v2025.03.14) |
| Mar 30, 2025 | 88.72% (0.88722) | 99.49th | v4 (v2025.03.14) |
| Mar 29, 2025 | 87.58% (0.87583) | 99.34th | v4 (v2025.03.14) |
| Mar 17, 2025 | 88.72% (0.88722) | 99.49th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00055) | 24.93th | v3 (v2023.03.01) |
| May 22, 2024 | 0.06% (0.00055) | 22.60th | v3 (v2023.03.01) |
| Mar 11, 2024 | 0.06% (0.00055) | 20.59th | v3 (v2023.03.01) |
| Jan 11, 2024 | 0.06% (0.00061) | 24.29th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00057) | 21.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.12% (0.03119) | 83.83th | v2 (v2022.01.01) |
| Aug 27, 2022 | 3.12% (0.03119) | 83.04th | v2 (v2022.01.01) |
| May 26, 2022 | 2.74% (0.02744) | 81.51th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.76% (0.02758) | 81.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.76% (0.02758) | 62.79th | v2 (v2022.01.01) |
References (26)
- http://blog.illumos.org/2012/06/14/illumos-vulnerability-patched/ x_refsource_CONFIRM
- http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/ x_refsource_CONFIRM
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2012-003.txt.asc vendor-advisoryx_refsource_NETBSD
- http://lists.xen.org/archives/html/xen-announce/2012-06/msg00001.html mailing-listx_refsource_MLIST
- http://lists.xen.org/archives/html/xen-devel/2012-06/msg01072.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/55082 third-party-advisoryx_refsource_SECUNIA
- http://security.freebsd.org/advisories/FreeBSD-SA-12:04.sysret.asc vendor-advisoryx_refsource_FREEBSD
- http://security.gentoo.org/glsa/glsa-201309-24.xml vendor-advisoryx_refsource_GENTOO
- http://smartos.org/2012/06/15/smartos-news-3/ x_refsource_CONFIRM
- http://support.citrix.com/article/CTX133161 x_refsource_CONFIRM
- http://wiki.smartos.org/display/DOC/SmartOS+Change+Log#SmartOSChangeLog-June14%2C2012 x_refsource_CONFIRM
- http://www.debian.org/security/2012/dsa-2501 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2012/dsa-2508 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/649219 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html x_refsource_CONFIRM
- http://www.us-cert.gov/cas/techalerts/TA12-164A.html third-party-advisoryx_refsource_CERTUS Government Resource
- https://access.redhat.com/security/cve/CVE-2012-0217 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=813428 x_refsource_CONFIRMIssue Tracking
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-042 vendor-advisoryx_refsource_MS
- https://nvd.nist.gov/vuln/detail/CVE-2012-0217
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15596 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2012-0217
- https://www.exploit-db.com/exploits/28718/ exploitx_refsource_EXPLOIT-DB
- https://www.exploit-db.com/exploits/46508/ exploitx_refsource_EXPLOIT-DB
- https://www.illumos.org/issues/2873 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.