CVE-2014-5146XEN vulnerability

CWE-39911 documents6 sources
Severity
4.7MEDIUMNVD
EPSS
0.1%
top 78.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateMay 14

Description

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages4 packages

debiandebian/xen< xen 4.4.1-4 (bookworm)
Debianxen/xen< 4.4.1-4+3
NVDxen/xen7 versions+6
NVDopensuse/opensuse13.1, 13.2+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-3jrv-3c97-g969: Certain MMU virtualization operations in Xen 42022-05-14
GHSA
GHSA-f96q-c56j-h692: Certain MMU virtualization operations in Xen 42022-05-14
OSV
CVE-2014-5149: Certain MMU virtualization operations in Xen 42014-08-22
OSV
CVE-2014-5146: Certain MMU virtualization operations in Xen 42014-08-22

📋Vendor Advisories

4
Red Hat
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)2014-08-12
Red Hat
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)2014-08-12
Debian
CVE-2014-5146: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa9...2014
Debian
CVE-2014-5149: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using sha...2014

💬Community

1
Bugzilla
CVE-2014-5146 CVE-2014-5149 xen: Long latency virtual-mmu operations are not preemptible (xsa-97)2014-07-29