CVE-2014-3714: Input Validation
The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3714?
CVE-2014-3714 is classified as a medium severity vulnerability due to the potential for denial of service and unauthorized memory access.
How do I fix CVE-2014-3714?
To fix CVE-2014-3714, upgrade to a patched version of Xen beyond 4.4.x that addresses the kernel length validation issue.
What kind of attacks can exploit CVE-2014-3714?
CVE-2014-3714 can be exploited through crafted 32-bit ARM guest kernel images, leading to memory reading or system crashes.
Which versions of Xen are affected by CVE-2014-3714?
CVE-2014-3714 affects Xen version 4.4.0 and 4.4.0-rc1.
Who is at risk from CVE-2014-3714?
Local users who have access to run 32-bit ARM guest kernels in affected Xen environments are at risk from CVE-2014-3714.