CVE-2014-1894: Integer Overflow
Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1891, CVE-2014-1892, and CVE-2014-1893.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1894?
CVE-2014-1894 has a medium severity due to its potential to cause denial of service through local exploit.
How do I fix CVE-2014-1894?
To fix CVE-2014-1894, upgrade to Xen versions later than 3.2.3 that address this vulnerability.
Which versions of Xen are affected by CVE-2014-1894?
CVE-2014-1894 affects Xen versions 3.0.2 to 3.2.3 and specific older versions like 3.0.3, 3.0.4, and 3.1.3 through 3.2.2.
Can CVE-2014-1894 be exploited remotely?
CVE-2014-1894 cannot be exploited remotely as it requires local user access to trigger the vulnerability.
What is the impact of CVE-2014-1894?
The impact of CVE-2014-1894 is primarily denial of service, leading to processor faults on affected Xen systems.