CVE-2014-5149XEN vulnerability

CWE-39911 documents6 sources
Severity
4.7MEDIUMNVD
EPSS
0.1%
top 78.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateMay 14

Description

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages4 packages

debiandebian/xen< xen 4.4.1-4 (bookworm)
Debianxen/xen< 4.4.1-4+3
NVDxen/xen7 versions+6
NVDopensuse/opensuse13.1, 13.2+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-3jrv-3c97-g969: Certain MMU virtualization operations in Xen 42022-05-14
GHSA
GHSA-f96q-c56j-h692: Certain MMU virtualization operations in Xen 42022-05-14
OSV
CVE-2014-5149: Certain MMU virtualization operations in Xen 42014-08-22
OSV
CVE-2014-5146: Certain MMU virtualization operations in Xen 42014-08-22

📋Vendor Advisories

4
Red Hat
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)2014-08-12
Red Hat
xen: Long latency virtual-mmu operations are not preemptible (xsa-97)2014-08-12
Debian
CVE-2014-5146: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x before the xsa9...2014
Debian
CVE-2014-5149: xen - Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using sha...2014

💬Community

1
Bugzilla
CVE-2014-5146 CVE-2014-5149 xen: Long latency virtual-mmu operations are not preemptible (xsa-97)2014-07-29