CVE-2014-4022: Infoleak
Published Jul 9, 2014
·Updated
The allocdomainstruct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOPsetuptable subhypercall.
Affected Software
2 affected components
XEN Xen=4.4.0
XEN Xen=4.4.0-rc1
Event History
Jul 9, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4022?
CVE-2014-4022 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-4022?
To fix CVE-2014-4022, update to a patched version of Xen that resolves this issue.
3
Which versions of Xen are affected by CVE-2014-4022?
CVE-2014-4022 affects Xen versions 4.4.0 and 4.4.0-rc1 on ARM platforms.
4
What type of vulnerability is CVE-2014-4022?
CVE-2014-4022 is a proper initialization vulnerability in the alloc_domain_struct function.
5
Who can exploit CVE-2014-4022?
Local guest administrators can exploit CVE-2014-4022 to obtain sensitive information.