CVE-2014-3967
published 2014-06-05CVE-2014-3967: The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest…
PriorityP415medium5.5CVSS 2.0
AVAACLAuSCNINAC
EPSS
0.71%
49.4th percentile
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-1 (bookworm) | xen 4.4.1-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
CVSS provenance
nvdv2.05.5MEDIUMAV:A/AC:L/Au:S/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg4x-g82c-qxqj: The HVMOP_inject_msi function in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2014-3967 [MEDIUM] GHSA-hg4x-g82c-qxqj: The HVMOP_inject_msi function in Xen 4
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.
OSV
CVE-2014-3967: The HVMOP_inject_msi function in Xen 4
osv·2014-06-05·CVSS 5.5
CVE-2014-3967 [MEDIUM] CVE-2014-3967: The HVMOP_inject_msi function in Xen 4
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.
Red Hat
xen: Vulnerabilities in HVM MSI injection (XSA-96)
vendor_redhat·2014-06-03·CVSS 5.5
CVE-2014-3967 [MEDIUM] xen: Vulnerabilities in HVM MSI injection (XSA-96)
xen: Vulnerabilities in HVM MSI injection (XSA-96)
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as
shipped with Red Hat Enterprise Linux 5.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat
Enterprise MRG 2 as we did not have support for Xen hypervisor.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-3967: xen - The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly c...
vendor_debian·2014·CVSS 5.5
CVE-2014-3967 [MEDIUM] CVE-2014-3967: xen - The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly c...
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed in 4.4.1-1)
trixie: resolved (fixed in 4.4.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3967 CVE-2014-3968 xen: Vulnerabilities in HVM MSI injection (XSA-96) [fedora-all]
bugzilla·2014-06-04·CVSS 5.5
CVE-2014-3967 [MEDIUM] CVE-2014-3967 CVE-2014-3968 xen: Vulnerabilities in HVM MSI injection (XSA-96) [fedora-all]
CVE-2014-3967 CVE-2014-3968 xen: Vulnerabilities in HVM MSI injection (XSA-96) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue aff
Bugzilla
CVE-2014-3967 CVE-2014-3968 xen: Vulnerabilities in HVM MSI injection (XSA-96)
bugzilla·2014-05-28·CVSS 5.5
CVE-2014-3967 [MEDIUM] CVE-2014-3967 CVE-2014-3968 xen: Vulnerabilities in HVM MSI injection (XSA-96)
CVE-2014-3967 CVE-2014-3968 xen: Vulnerabilities in HVM MSI injection (XSA-96)
The implementation of the HVM control operation HVMOP_inject_msi, while
checking whether a particular IRQ was already set up in the necessary
way, fails to properly check all respective conditions. In particular
it doesn't check the returned pointer for being non-NULL before de-
referencing it.
Furthermore that same code also handles certain errors by logging
messages, without (under default settings) at least making these
messages subject to rate limiting.
The NULL pointer de-reference would lead to a host crash, and hence a
denial of service would result.
The spamming of the hypervisor log could similarly lead to a denial of
service.
Acknowledgements:
Red Hat would like to thank the Xen project for repor
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134710.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134739.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlhttp://www.openwall.com/lists/oss-security/2014/06/04/13http://www.securityfocus.com/bid/67794http://www.securitytracker.com/id/1030322http://xenbits.xen.org/xsa/advisory-96.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134710.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134739.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00003.htmlhttp://www.openwall.com/lists/oss-security/2014/06/04/13http://www.securityfocus.com/bid/67794http://www.securitytracker.com/id/1030322http://xenbits.xen.org/xsa/advisory-96.htmlhttps://security.gentoo.org/glsa/201504-04
2014-06-05
Published