CVE-2014-1895
published 2014-04-01CVE-2014-1895: Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in…
PriorityP417medium5.8CVSS 2.0
AVAACMAuSCPINAC
EPSS
0.53%
41.0th percentile
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:A/AC:M/Au:S/C:P/I:N/A:C
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h86q-v7x4-qx4x: Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op
ghsa_unreviewed·2022-05-17
CVE-2014-1895 [MEDIUM] GHSA-h86q-v7x4-qx4x: Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
OSV
CVE-2014-1895: Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op
osv·2014-04-01·CVSS 5.8
CVE-2014-1895 [MEDIUM] CVE-2014-1895: Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
Red Hat
xen: Off-by-one error in FLASK_AVC_CACHESTAT hypercall (xsa-85)
vendor_redhat·2014-02-06·CVSS 5.8
CVE-2014-1895 [MEDIUM] CWE-193 xen: Off-by-one error in FLASK_AVC_CACHESTAT hypercall (xsa-85)
xen: Off-by-one error in FLASK_AVC_CACHESTAT hypercall (xsa-85)
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-1895: xen - Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flas...
vendor_debian·2014·CVSS 5.8
CVE-2014-1895 [MEDIUM] CVE-2014-1895: xen - Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flas...
Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2014/02/07/12http://www.openwall.com/lists/oss-security/2014/02/10/6http://xenbits.xen.org/xsa/advisory-85.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2014/02/07/12http://www.openwall.com/lists/oss-security/2014/02/10/6http://xenbits.xen.org/xsa/advisory-85.html
2014-04-01
Published