CVE-2014-1896 — Improper Input Validation in XEN
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 65.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 1
Latest updateMay 17
Description
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."
CVSS vector
AV:A/AC:M/C:P/I:P/A:PExploitability: 4.4 | Impact: 6.4