Input validation error in Debian products - CVE-2014-8595
Published: November 19, 2014 / Updated: August 9, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
Affected software
Opensuse
Debian Linux
Gentoo Linux
SUSE Linux
Fedora
xen
How to mitigate CVE-2014-8595
External References
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.html
- http://secunia.com/advisories/62537
- http://secunia.com/advisories/62672
- http://support.citrix.com/article/CTX200288
- http://support.citrix.com/article/CTX201794
- http://www.debian.org/security/2015/dsa-3140
- http://www.securityfocus.com/bid/71151
- http://xenbits.xen.org/xsa/advisory-110.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98768
- https://security.gentoo.org/glsa/201504-04