CVE Vulnerabilities

CVE-2014-7155

Published: Oct 02, 2014 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.

Affected Software

Name Vendor Start Version End Version
Xen Xen 3.2.0 3.2.0
Xen Xen 4.1.5 4.1.5
Xen Xen 3.2.1 3.2.1
Xen Xen 4.2.2 4.2.2
Xen Xen 4.2.3 4.2.3
Xen Xen 3.0.4 3.0.4
Xen Xen 3.4.0 3.4.0
Xen Xen 4.3.0 4.3.0
Xen Xen 4.0.4 4.0.4
Xen Xen 4.0.2 4.0.2
Xen Xen 3.3.2 3.3.2
Xen Xen 4.1.2 4.1.2
Xen Xen 3.2.2 3.2.2
Xen Xen 3.4.4 3.4.4
Xen Xen 4.0.0 4.0.0
Xen Xen 4.4.0 4.4.0
Xen Xen 4.1.1 4.1.1
Xen Xen 4.2.0 4.2.0
Xen Xen 4.1.0 4.1.0
Xen Xen 3.4.3 3.4.3
Xen Xen 3.0.3 3.0.3
Xen Xen 4.1.3 4.1.3
Xen Xen 3.2.3 3.2.3
Xen Xen 4.1.6.1 4.1.6.1
Xen Xen * 4.4.0
Xen Xen 3.3.1 3.3.1
Xen Xen 3.0.2 3.0.2
Xen Xen 3.4.2 3.4.2
Xen Xen 4.1.4 4.1.4
Xen Xen 3.4.1 3.4.1
Xen Xen 3.1.4 3.1.4
Xen Xen 4.3.1 4.3.1
Xen Xen 3.3.0 3.3.0
Xen Xen 4.2.1 4.2.1
Xen Xen 3.1.3 3.1.3
Xen Xen 4.4.0 4.4.0
Xen Xen 4.0.1 4.0.1
Xen Xen 4.0.3 4.0.3

References