Vulnerability CVE-2014-5147: Information

Description

Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.

Severity: MEDIUM (4.3)

Published: Aug. 29, 2014
Modified: Oct. 30, 2018
Error type identifier: CWE-264

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
xenp104.4.1-alt14.14.1-alt2ALT-PU-2014-2061-1128919Fixed
xenp94.4.1-alt14.10.3-alt1ALT-PU-2014-2061-1128919Fixed
xenc10f14.4.1-alt14.14.1-alt2ALT-PU-2014-2061-1128919Fixed
xenc9f24.4.1-alt14.10.3-alt1ALT-PU-2014-2061-1128919Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
http://xenbits.xen.org/xsa/advisory-102.html
  • Patch
  • Vendor Advisory
1030724
      1. Configuration 1

        cpe:2.3:o:xen:xen:4.4.0:rc1:*:*:*:*:*:*

        cpe:2.3:o:xen:xen:4.4.0:*:*:*:*:*:*:*