Permissions, Privileges, and Access Controls in Xen - CVE-2014-2915

 

Permissions, Privileges, and Access Controls in Xen - CVE-2014-2915

Published: April 24, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41754
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-2915
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to perform a denial of service (DoS) attack.

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.


Affected software

Xen

How to mitigate CVE-2014-2915

Install update from vendor's website.


External References

Related Security Bulletins