CVE Vulnerabilities

CVE-2014-3967

Published: Jun 05, 2014 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:A/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
5.2 MODERATE
AV:A/AC:M/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM

The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Xen Xen 4.2.0 (including) 4.2.0 (including)
Xen Xen 4.2.1 (including) 4.2.1 (including)
Xen Xen 4.2.2 (including) 4.2.2 (including)
Xen Xen 4.2.3 (including) 4.2.3 (including)
Xen Ubuntu devel *
Xen Ubuntu saucy *
Xen Ubuntu trusty *
Xen-3.3 Ubuntu upstream *

References