CVE Vulnerabilities

CVE-2014-3124

Published: May 07, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.7 MEDIUM
AV:A/AC:L/Au:S/C:P/I:P/A:C
RedHat/V2
4.3 MODERATE
AV:A/AC:H/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.

Affected Software

NameVendorStart VersionEnd Version
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.1.5 (including)4.1.5 (including)
XenXen4.1.6.1 (including)4.1.6.1 (including)
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenXen4.2.2 (including)4.2.2 (including)
XenXen4.2.3 (including)4.2.3 (including)
XenXen4.3.0 (including)4.3.0 (including)
XenXen4.3.1 (including)4.3.1 (including)
XenXen4.4.0 (including)4.4.0 (including)
XenXen4.4.0-rc1 (including)4.4.0-rc1 (including)
XenUbuntudevel*
XenUbuntuprecise*
XenUbuntuquantal*
XenUbuntusaucy*
XenUbuntutrusty*
Xen-3.3Ubuntuupstream*

References