CVE-2014-5148
published 2014-10-26CVE-2014-5148: Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.40%
32.8th percentile
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-1 (bookworm) | xen 4.4.1-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
| xen | xen | >= 0 < 4.4.1-1 | 4.4.1-1 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-5148: xen - Xen 4.4.x, when running on an ARM system and "handling an unknown system registe...
vendor_debian·2014·CVSS 4.6
CVE-2014-5148 [MEDIUM] CVE-2014-5148: xen - Xen 4.4.x, when running on an ARM system and "handling an unknown system registe...
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.
Scope: local
bookworm: resolved (fixed in 4.4.1-1)
bullseye: resolved (fixed in 4.4.1-1)
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed in 4.4.1-1)
trixie: resolved (fixed in 4.4.1-1)
Red Hat
CVE-2014-5148: Xen 4
vendor_redhat·CVSS 4.6
CVE-2014-5148 [MEDIUM] CVE-2014-5148: Xen 4
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.
Statement: Not vulnerable. This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
GHSA
GHSA-35mg-4h75-f9m6: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2014-5148 [MEDIUM] CWE-119 GHSA-35mg-4h75-f9m6: Xen 4
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.
OSV
CVE-2014-5148: Xen 4
osv·2014-10-26·CVSS 4.6
CVE-2014-5148 [MEDIUM] CVE-2014-5148: Xen 4
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59934http://www.securityfocus.com/bid/69189http://www.securitytracker.com/id/1030725http://xenbits.xenproject.org/xsa/advisory-103.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95233http://secunia.com/advisories/59934http://www.securityfocus.com/bid/69189http://www.securitytracker.com/id/1030725http://xenbits.xenproject.org/xsa/advisory-103.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/95233
2014-10-26
Published