CVE-2014-1642
published 2014-01-26CVE-2014-1642: The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be…
PriorityP420medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.44%
36.3th percentile
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjr7-r3wr-cjpp: The IRQ setup in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2014-1642 [MEDIUM] GHSA-gjr7-r3wr-cjpp: The IRQ setup in Xen 4
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
OSV
CVE-2014-1642: The IRQ setup in Xen 4
osv·2014-01-26·CVSS 4.4
CVE-2014-1642 [MEDIUM] CVE-2014-1642: The IRQ setup in Xen 4
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
Red Hat
xen: out-of-memory condition yielding memory corruption during IRQ setup
vendor_redhat·2014-01-23·CVSS 4.4
CVE-2014-1642 [MEDIUM] xen: out-of-memory condition yielding memory corruption during IRQ setup
xen: out-of-memory condition yielding memory corruption during IRQ setup
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterpri
Debian
CVE-2014-1642: xen - The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configur...
vendor_debian·2014·CVSS 4.4
CVE-2014-1642 [MEDIUM] CVE-2014-1642: xen - The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configur...
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1642 xen: out-of-memory condition yielding memory corruption during IRQ setup [fedora-all]
bugzilla·2014-01-23·CVSS 4.4
CVE-2014-1642 [MEDIUM] CVE-2014-1642 xen: out-of-memory condition yielding memory corruption during IRQ setup [fedora-all]
CVE-2014-1642 xen: out-of-memory condition yielding memory corruption during IRQ setup [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pleas
Bugzilla
CVE-2014-1642 xen: out-of-memory condition yielding memory corruption during IRQ setup
bugzilla·2014-01-23·CVSS 4.4
CVE-2014-1642 [MEDIUM] CVE-2014-1642 xen: out-of-memory condition yielding memory corruption during IRQ setup
CVE-2014-1642 xen: out-of-memory condition yielding memory corruption during IRQ setup
When setting up the IRQ for a passed through physical device, a flaw in the error handling could result in a memory allocation being used after it is freed, and then freed a second time.
Malicious guest administrators can trigger a use-after-free error, resulting in hypervisor memory corruption.
Reference:
http://www.openwall.com/lists/oss-security/2014/01/23/2
CVE assignment:
http://www.openwall.com/lists/oss-security/2014/01/23/3
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127580.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/127607.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://osvdb.org/102406http://secunia.com/advisories/56557http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2014/01/23/4http://www.securityfocus.com/bid/65097http://www.securitytracker.com/id/1029679http://xenbits.xen.org/xsa/advisory-83.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/90649http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127580.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/127607.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://osvdb.org/102406http://secunia.com/advisories/56557http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2014/01/23/4http://www.securityfocus.com/bid/65097http://www.securitytracker.com/id/1029679http://xenbits.xen.org/xsa/advisory-83.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/90649
2014-01-26
Published