CVE-2014-1891: Integer Overflow
Multiple integer overflows in the (1) FLASKGETBOOL, (2) FLASKSETBOOL, (3) FLASKUSER, and (4) FLASKCONTEXTTOSID suboperations in the flask hypercall in Xen 4.3.x, 4.2.x, 4.1.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1892, CVE-2014-1893, and CVE-2014-1894.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1891?
CVE-2014-1891 has a high severity due to its potential to cause a denial of service through processor faults.
How do I fix CVE-2014-1891?
To fix CVE-2014-1891, upgrade to a patched version of Xen that resolves the integer overflow vulnerabilities.
Which versions of Xen are affected by CVE-2014-1891?
CVE-2014-1891 affects Xen versions 3.2.x, 4.1.x, 4.2.x, and 4.3.x, among others.
What kind of issues can CVE-2014-1891 cause?
CVE-2014-1891 can lead to denial of service attacks due to integer overflows in specific hypercall suboperations.
Is XSM required to exploit CVE-2014-1891?
Yes, XSM (Xen Security Modules) must be enabled for the vulnerabilities described in CVE-2014-1891 to be exploited.