CVE-2014-5147: Medium severity xen xapi vulnerability
Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5147?
CVE-2014-5147 has a moderate severity level due to its potential to cause a denial of service by crashing the host system.
How do I fix CVE-2014-5147?
To fix CVE-2014-5147, upgrade to Xen version 4.4.1 or later where the vulnerability has been addressed.
Who is affected by CVE-2014-5147?
CVE-2014-5147 affects users running Xen 4.4.0 and 4.4.0-rc1 with a 64-bit kernel on ARM systems.
What impact does CVE-2014-5147 have on my system?
CVE-2014-5147 can allow local guest users to crash the host system, leading to a denial of service.
Is there a workaround for CVE-2014-5147?
Currently, the recommended action for CVE-2014-5147 is to apply the available patches or upgrade Xen to a secure version.