PT-2014-4351 · Xen+1 · Xen+1

Published

2014-04-01

·

Updated

2017-01-07

·

CVE-2014-1896

CVSS v2.0

4.9

Medium

VectorAV:A/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 4.2.x through 4.4-RC
Description The issue is related to the do send and do recv functions in io.c in libvchan, which allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes. This triggers a "read or write past the end of the ring."
Recommendations For Xen versions 4.2.x through 4.4-RC, consider restricting access to the vulnerable do send and do recv functions in io.c in libvchan as a temporary workaround until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1896

Affected Products

Suse
Xen