CVE Vulnerabilities

CVE-2014-7188

Published: Oct 02, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.3 HIGH
AV:A/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
5.8 IMPORTANT
AV:A/AC:M/Au:S/C:P/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.1.5 (including)4.1.5 (including)
XenXen4.1.6.1 (including)4.1.6.1 (including)
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenXen4.2.2 (including)4.2.2 (including)
XenXen4.2.3 (including)4.2.3 (including)
XenXen4.3.0 (including)4.3.0 (including)
XenXen4.3.1 (including)4.3.1 (including)
XenXen4.4.0 (including)4.4.0 (including)
XenXen4.4.0-rc1 (including)4.4.0-rc1 (including)
XenXen4.4.1 (including)4.4.1 (including)
XenUbuntudevel*
XenUbuntuprecise*
XenUbuntutrusty*
XenUbuntuutopic*
XenUbuntuvivid*
Xen-3.3Ubuntulucid*
Xen-3.3Ubuntuupstream*

References