cbcvebase.
CVE-2014-8594
published 2014-11-19

CVE-2014-8594: The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests…

PriorityP425medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
2.22%
80.8th percentile
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation services for HVM guests using Hardware Assisted Paging (HAP).

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianxen< xen 4.4.1-4 (bookworm)xen 4.4.1-4 (bookworm)
opensuseopensuse
opensuseopensuse
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.4.1-44.4.1-4
xenxen>= 0 < 4.4.1-44.4.1-4
xenxen>= 0 < 4.4.1-44.4.1-4

CVSS provenance

nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.4MEDIUM
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.