cbcvebase.
CVE-2014-5147
published 2014-08-29

CVE-2014-5147: Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows…

PriorityP413medium4.3CVSS 2.0
AVAACHAuSCNINAC
EPSS
0.43%
34.5th percentile
Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.4.1-1 (bookworm)xen 4.4.1-1 (bookworm)
xenxen
xenxen>= 0 < 4.4.1-14.4.1-1
xenxen>= 0 < 4.4.1-14.4.1-1
xenxen>= 0 < 4.4.1-14.4.1-1
xenxen>= 0 < 4.4.1-14.4.1-1

CVSS provenance

nvdv2.04.3MEDIUMAV:A/AC:H/Au:S/C:N/I:N/A:C
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.