CVE-2014-3124
published 2014-05-07CVE-2014-3124: The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly…
PriorityP424medium6.7CVSS 2.0
AVAACLAuSCPIPAC
EPSS
0.81%
53.2th percentile
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-1 (bookworm) | xen 4.4.1-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
CVSS provenance
nvdv2.06.7MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92)
vendor_redhat·2014-04-29·CVSS 6.7
CVE-2014-3124 [MEDIUM] xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92)
xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92)
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-3124: xen - The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM a...
vendor_debian·2014·CVSS 6.7
CVE-2014-3124 [MEDIUM] CVE-2014-3124: xen - The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM a...
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed in 4.4.1-1)
trixie: resolved (fixed in 4.4.1-1)
GHSA
GHSA-4qq6-r634-f5m4: The HVMOP_set_mem_type control in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2014-3124 [MEDIUM] GHSA-4qq6-r634-f5m4: The HVMOP_set_mem_type control in Xen 4
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
OSV
CVE-2014-3124: The HVMOP_set_mem_type control in Xen 4
osv·2014-05-07·CVSS 6.7
CVE-2014-3124 [MEDIUM] CVE-2014-3124: The HVMOP_set_mem_type control in Xen 4
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3124 xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92) [fedora-all]
bugzilla·2014-05-01·CVSS 6.7
CVE-2014-3124 [MEDIUM] CVE-2014-3124 xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92) [fedora-all]
CVE-2014-3124 xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2014-3124 xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92)
bugzilla·2014-04-16·CVSS 6.7
CVE-2014-3124 [MEDIUM] CVE-2014-3124 xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92)
CVE-2014-3124 xen: hypervisor: HVMOP_set_mem_type allows invalid P2M entries to be created (XSA-92)
The implementation in Xen of the HVMOP_set_mem_type HVM control
operations attempts to exclude transitioning a page from an
inappropriate memory type. However, only an inadequate subset of
memory types is excluded.
There are certain other types that don't correspond to a particular
valid page, whose page table translation can be inappropriately
changed (by HVMOP_set_mem_type) from not-present (due to the lack of
valid memory page) to present. If this occurs, an invalid translation
will be established.
A malicious administrator of a domain privileged with regard to an
HVM guest can cause Xen to crash leading to a Denial of Service.
Arbitrary code execution, and therefore privilege escalat
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/133148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/133191.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2014/04/29/1http://www.openwall.com/lists/oss-security/2014/04/30/10http://www.securityfocus.com/bid/67113http://www.securitytracker.com/id/1030160http://xenbits.xen.org/xsa/advisory-92.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/133148.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/133191.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlhttp://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.debian.org/security/2014/dsa-3006http://www.openwall.com/lists/oss-security/2014/04/29/1http://www.openwall.com/lists/oss-security/2014/04/30/10http://www.securityfocus.com/bid/67113http://www.securitytracker.com/id/1030160http://xenbits.xen.org/xsa/advisory-92.html
2014-05-07
Published