CVE-2014-5146
published 2014-08-22CVE-2014-5146: Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.43%
34.5th percentile
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-4 (bookworm) | xen 4.4.1-4 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-4 | 4.4.1-4 |
| xen | xen | >= 0 < 4.4.1-4 | 4.4.1-4 |
| xen | xen | >= 0 < 4.4.1-4 | 4.4.1-4 |
| xen | xen | >= 0 < 4.4.1-4 | 4.4.1-4 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)
vendor_redhat·2014-08-12·CVSS 4.7
CVE-2014-5149 [MEDIUM] xen: Long latency virtual-mmu operations are not preemptible (xsa-97)
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
Statement: Not vulnerable.
This issue does not affect the versions of the kernel-xen package as shipped
with Red Hat Enterprise Linux 5.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Red Hat
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)
vendor_redhat·2014-08-12·CVSS 4.7
CVE-2014-5146 [MEDIUM] xen: Long latency virtual-mmu operations are not preemptible (xsa-97)
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
Statement: Not vulnerable.
This issue does not affect the versions of the kernel-xen package as shipped
with Red Hat Enterprise Linux 5.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-5146: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa9...
vendor_debian·2014·CVSS 4.7
CVE-2014-5146 [MEDIUM] CVE-2014-5146: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa9...
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
Scope: local
bookworm: resolved (fixed in 4.4.1-4)
bullseye: resolved (fixed in 4.4.1-4)
forky: resolved (fixed in 4.4.1-4)
sid: resolved (fixed in 4.4.1-4)
trixie: resolved (fixed in 4.4.1-4)
Debian
CVE-2014-5149: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using sha...
vendor_debian·2014·CVSS 4.7
CVE-2014-5149 [MEDIUM] CVE-2014-5149: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using sha...
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
Scope: local
bookworm: resolved (fixed in 4.4.1-4)
bullseye: resolved (fixed in 4.4.1-4)
forky: resolved (fixed in 4.4.1-4)
sid: resolved (fixed in 4.4.1-4)
trixie: resolved (fixed in 4.4.1-4)
GHSA
GHSA-3jrv-3c97-g969: Certain MMU virtualization operations in Xen 4
ghsa_unreviewed·2022-05-14·CVSS 4.7
CVE-2014-5149 [MEDIUM] GHSA-3jrv-3c97-g969: Certain MMU virtualization operations in Xen 4
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
GHSA
GHSA-f96q-c56j-h692: Certain MMU virtualization operations in Xen 4
ghsa_unreviewed·2022-05-14·CVSS 4.7
CVE-2014-5146 [MEDIUM] GHSA-f96q-c56j-h692: Certain MMU virtualization operations in Xen 4
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
OSV
CVE-2014-5149: Certain MMU virtualization operations in Xen 4
osv·2014-08-22·CVSS 4.7
CVE-2014-5149 [MEDIUM] CVE-2014-5149: Certain MMU virtualization operations in Xen 4
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
OSV
CVE-2014-5146: Certain MMU virtualization operations in Xen 4
osv·2014-08-22·CVSS 4.7
CVE-2014-5146 [MEDIUM] CVE-2014-5146: Certain MMU virtualization operations in Xen 4
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136980.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136981.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://www.securityfocus.com/bid/69198http://www.securitytracker.com/id/1030723http://xenbits.xen.org/xsa/advisory-97.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95234https://security.gentoo.org/glsa/201504-04http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136980.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136981.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://www.securityfocus.com/bid/69198http://www.securitytracker.com/id/1030723http://xenbits.xen.org/xsa/advisory-97.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95234https://security.gentoo.org/glsa/201504-04
2014-08-22
Published