#VU41812 Resource management error in Xen - CVE-2014-2580
Published: April 16, 2014 / Updated: August 10, 2020
Xen
Xen Project
Description
The vulnerability allows a local #AU# to perform a denial of service (DoS) attack.
The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which causes a mutex to be taken when trying to disable the interface.