CVE-2014-1896
published 2014-04-01CVE-2014-1896: The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or…
PriorityP420medium4.9CVSS 2.0
AVAACMAuSCPIPAP
EPSS
0.54%
41.6th percentile
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:A/AC:M/Au:S/C:P/I:P/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: libvchan failure handling malicious ring indexes (xsa-86)
vendor_redhat·2014-02-06·CVSS 4.9
CVE-2014-1896 [MEDIUM] xen: libvchan failure handling malicious ring indexes (xsa-86)
xen: libvchan failure handling malicious ring indexes (xsa-86)
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."
Statement: Not vulnerable.
This issue does not affect the versions of the xen package as shipped with Red Hat Enterprise Linux 5 as it does not provide oxenstored.
This issue does not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-1896: xen - The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3....
vendor_debian·2014·CVSS 4.9
CVE-2014-1896 [MEDIUM] CVE-2014-1896: xen - The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3....
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
GHSA
GHSA-8xr2-qvfg-j8q4: The (1) do_send and (2) do_recv functions in io
ghsa_unreviewed·2022-05-17
CVE-2014-1896 [MEDIUM] CWE-20 GHSA-8xr2-qvfg-j8q4: The (1) do_send and (2) do_recv functions in io
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."
OSV
CVE-2014-1896: The (1) do_send and (2) do_recv functions in io
osv·2014-04-01·CVSS 4.9
CVE-2014-1896 [MEDIUM] CVE-2014-1896: The (1) do_send and (2) do_recv functions in io
The (1) do_send and (2) do_recv functions in io.c in libvchan in Xen 4.2.x, 4.3.x, and 4.4-RC series allows local guests to cause a denial of service or possibly gain privileges via crafted xenstore ring indexes, which triggers a "read or write past the end of the ring."
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2014/02/07/12http://www.openwall.com/lists/oss-security/2014/02/10/7http://xenbits.xen.org/xsa/advisory-86.htmlhttp://xenbits.xen.org/xsa/xsa86.patchhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2014/02/07/12http://www.openwall.com/lists/oss-security/2014/02/10/7http://xenbits.xen.org/xsa/advisory-86.htmlhttp://xenbits.xen.org/xsa/xsa86.patch
2014-04-01
Published