CVE-2014-3716: Input Validation
Published May 19, 2014
·Updated
Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel.
Affected Software
2 affected components
XEN Xen=4.4.0
XEN Xen=4.4.0-rc1
Remediation
Patch Available
Event History
May 19, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3716?
CVE-2014-3716 has a severity rating that indicates it can cause a denial of service in a 32-bit guest kernel.
2
How do I fix CVE-2014-3716?
To fix CVE-2014-3716, upgrade to a version of Xen that is not affected, specifically versions beyond 4.4.x.
3
Who is affected by CVE-2014-3716?
CVE-2014-3716 affects local users running 32-bit guest kernels on Xen 4.4.x.
4
What vulnerabilities does CVE-2014-3716 exploit?
CVE-2014-3716 exploits improper alignment checks in the DTB header.
5
Can CVE-2014-3716 be exploited remotely?
CVE-2014-3716 cannot be exploited remotely as it requires local user access to the affected system.