CVE-2014-8595Missing Authorization in XEN

Severity
1.9LOWNVD
EPSS
0.1%
top 78.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateMay 14

Description

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.

CVSS vector

AV:L/AC:M/C:N/I:N/A:PExploitability: 3.4 | Impact: 2.9

Affected Packages4 packages

debiandebian/xen< xen 4.4.1-4 (bookworm)
Debianxen/xen< 4.4.1-4+3
NVDxen/xen30 versions+29
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Debian Linux 7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6qqc-xj3c-9jj8: arch/x86/x86_emulate/x86_emulate2022-05-14
OSV
CVE-2014-8595: arch/x86/x86_emulate/x86_emulate2014-11-19

📋Vendor Advisories

2
Red Hat
kernel: xen: Missing privilege level checks in x86 emulation of far branches (xsa110)2014-11-18
Debian
CVE-2014-8595: xen - arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly ...2014

💬Community

2
Bugzilla
CVE-2014-8595 kernel: xen: Missing privilege level checks in x86 emulation of far branches (xsa110) [fedora-all]2014-11-18
Bugzilla
CVE-2014-8595 kernel: xen: Missing privilege level checks in x86 emulation of far branches (xsa110)2014-11-05