CVE-2014-5146 — XEN vulnerability
Severity
4.7MEDIUMNVD
EPSS
0.1%
top 78.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateMay 14
Description
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa97-hap patch, when using Hardware Assisted Paging (HAP), are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5149.
CVSS vector
AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
4💬Community
1Bugzilla▶
CVE-2014-5146 CVE-2014-5149 xen: Long latency virtual-mmu operations are not preemptible (xsa-97)↗2014-07-29