PT-2014-7810 · Xen+1 · Xen+1

Andrei Lutas

·

Published

2014-10-02

·

Updated

2024-06-15

·

CVE-2014-7155

CVSS v2.0

5.8

Medium

VectorAV:A/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 4.4.x and earlier
Description The issue is related to the x86 emulate function in Xen, which does not properly check supervisor mode permissions. This allows local HVM users to cause a denial of service, resulting in a guest crash, or gain guest kernel mode privileges. The exploitation vectors involve specific instructions, including HLT, LGDT, LIDT, or LMSW.
Recommendations For Xen versions 4.4.x and earlier, consider restricting the use of the x86 emulate function until a patch is available. As a temporary workaround, limiting the execution of HLT, LGDT, LIDT, or LMSW instructions may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7155
DSA-3041-1
OPENSUSE-SU-2014_1279-1
OPENSUSE-SU-2014_1281-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2015:0940-1

Affected Products

Suse
Xen