cbcvebase.
CVE-2014-7155
published 2014-10-02

CVE-2014-7155: The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local…

PriorityP421medium5.8CVSS 2.0
AVAACLAuNCPIPAP
EPSS
0.97%
57.9th percentile
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianxen< xen 4.4.1-3 (bookworm)xen 4.4.1-3 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
xenxen<= 4.4.0
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen

CVSS provenance

nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.