CVE-2014-9065
published 2014-12-09CVE-2014-9065: common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service…
PriorityP414medium4.4CVSS 2.0
AVLACMAuSCNINAC
EPSS
0.37%
29.7th percentile
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.1-6 (bookworm) | xen 4.4.1-6 (bookworm) |
| debian | xen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| xen | xen | <= 4.4.1 | — |
| xen | xen | >= 0 < 4.4.1-6 | 4.4.1-6 |
| xen | xen | >= 0 < 4.4.1-6 | 4.4.1-6 |
| xen | xen | >= 0 < 4.4.1-6 | 4.4.1-6 |
| xen | xen | >= 0 < 4.4.1-6 | 4.4.1-6 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:S/C:N/I:N/A:C
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: p2m lock starvation (xsa114)
vendor_redhat·2014-12-08·CVSS 4.4
CVE-2014-9066 [MEDIUM] CWE-667 xen: p2m lock starvation (xsa114)
xen: p2m lock starvation (xsa114)
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Red Hat
xen: p2m lock starvation (xsa114)
vendor_redhat·2014-12-08·CVSS 4.4
CVE-2014-9065 [MEDIUM] CWE-667 xen: p2m lock starvation (xsa114)
xen: p2m lock starvation (xsa114)
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-9066: xen - Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly han...
vendor_debian·2014·CVSS 4.4
CVE-2014-9066 [MEDIUM] CVE-2014-9066: xen - Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly han...
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2014-9065: xen - common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and wri...
vendor_debian·2014·CVSS 4.4
CVE-2014-9065 [MEDIUM] CVE-2014-9065: xen - common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and wri...
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
Scope: local
bookworm: resolved (fixed in 4.4.1-6)
bullseye: resolved (fixed in 4.4.1-6)
forky: resolved (fixed in 4.4.1-6)
sid: resolved (fixed in 4.4.1-6)
trixie: resolved (fixed in 4.4.1-6)
GHSA
GHSA-4f7c-f5r2-23hx: Xen 4
ghsa_unreviewed·2022-05-14·CVSS 4.4
CVE-2014-9066 [MEDIUM] GHSA-4f7c-f5r2-23hx: Xen 4
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
GHSA
GHSA-gq6c-wcjg-9p8q: common/spinlock
ghsa_unreviewed·2022-05-14·CVSS 4.7
CVE-2014-9065 [MEDIUM] GHSA-gq6c-wcjg-9p8q: common/spinlock
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
OSV
CVE-2014-9065: common/spinlock
osv·2014-12-09·CVSS 4.4
CVE-2014-9065 [MEDIUM] CVE-2014-9065: common/spinlock
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
OSV
CVE-2014-9066: Xen 4
osv·2014-12-09·CVSS 4.4
CVE-2014-9066 [MEDIUM] CVE-2014-9066: Xen 4
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://www.openwall.com/lists/oss-security/2014/12/08/4http://www.securityfocus.com/bid/71544http://xenbits.xen.org/xsa/advisory-114.htmlhttps://security.gentoo.org/glsa/201504-04http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlhttp://www.openwall.com/lists/oss-security/2014/12/08/4http://www.securityfocus.com/bid/71544http://xenbits.xen.org/xsa/advisory-114.htmlhttps://security.gentoo.org/glsa/201504-04
2014-12-09
Published