Resource management error in Xen - CVE-2014-2580

 

Resource management error in Xen - CVE-2014-2580

Published: April 16, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41812
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2014-2580
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Xen Project
Affected software:
Xen

Detailed vulnerability description

The vulnerability allows a local #AU# to perform a denial of service (DoS) attack.

The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which causes a mutex to be taken when trying to disable the interface.


How to mitigate CVE-2014-2580

Install update from vendor's website.

Sources