CVE-2014-8867
published 2014-12-01CVE-2014-8867: The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.46%
37.8th percentile
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.4.1-5 (bookworm) | xen 4.4.1-5 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| xen | xen | <= 3.2.0 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.1-5 | 4.4.1-5 |
| xen | xen | >= 0 < 4.4.1-5 | 4.4.1-5 |
| xen | xen | >= 0 < 4.4.1-5 | 4.4.1-5 |
| xen | xen | >= 0 < 4.4.1-5 | 4.4.1-5 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj57-646v-244j: The acceleration support for the "REP MOVS" instruction in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2014-8867 [MEDIUM] GHSA-jj57-646v-244j: The acceleration support for the "REP MOVS" instruction in Xen 4
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
OSV
CVE-2014-8867: The acceleration support for the "REP MOVS" instruction in Xen 4
osv·2014-12-01·CVSS 4.9
CVE-2014-8867 [MEDIUM] CVE-2014-8867: The acceleration support for the "REP MOVS" instruction in Xen 4
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
Red Hat
xen: Insufficient bounding of "REP MOVS" to MMIO emulated inside the hypervisor (xsa112)
vendor_redhat·2014-11-27·CVSS 4.9
CVE-2014-8867 [MEDIUM] xen: Insufficient bounding of "REP MOVS" to MMIO emulated inside the hypervisor (xsa112)
xen: Insufficient bounding of "REP MOVS" to MMIO emulated inside the hypervisor (xsa112)
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
An insufficient bound checking flaw was found in the Xen hypervisor's implementation of acceleration support for the "REP MOVS" instructions. A privileged HVM guest user could potentially use this flaw to crash the host.
Statement: This issue does affect the versions of the kernel-xen package as shipped with
Red Hat Enterprise Linux 5. Future kernel-xen updates for Red Hat Enterprise
Linux 5 may address this issue.
Debian
CVE-2014-8867: xen - The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and...
vendor_debian·2014·CVSS 4.9
CVE-2014-8867 [MEDIUM] CVE-2014-8867: xen - The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and...
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.4.1-5)
bullseye: resolved (fixed in 4.4.1-5)
forky: resolved (fixed in 4.4.1-5)
sid: resolved (fixed in 4.4.1-5)
trixie: resolved (fixed in 4.4.1-5)
No detection rules found.
No public exploits indexed.
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0783.htmlhttp://secunia.com/advisories/59949http://secunia.com/advisories/62672http://support.citrix.com/article/CTX200288http://support.citrix.com/article/CTX201794http://www.debian.org/security/2015/dsa-3140http://www.securityfocus.com/bid/71331http://xenbits.xenproject.org/xsa/advisory-112.htmlhttps://security.gentoo.org/glsa/201504-04http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0783.htmlhttp://secunia.com/advisories/59949http://secunia.com/advisories/62672http://support.citrix.com/article/CTX200288http://support.citrix.com/article/CTX201794http://www.debian.org/security/2015/dsa-3140http://www.securityfocus.com/bid/71331http://xenbits.xenproject.org/xsa/advisory-112.htmlhttps://security.gentoo.org/glsa/201504-04
2014-12-01
Published