cbcvebase.
CVE-2014-7156
published 2014-10-02

CVE-2014-7156: The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that…

PriorityP49low3.3CVSS 2.0
AVAACLAuNCNINAP
EPSS
0.85%
53.8th percentile
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.4.1-3 (bookworm)xen 4.4.1-3 (bookworm)
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.4.1-34.4.1-3
xenxen>= 0 < 4.4.1-34.4.1-3
xenxen>= 0 < 4.4.1-34.4.1-3
xenxen>= 0 < 4.4.1-34.4.1-3

CVSS provenance

nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.