CVE-2014-5148: Buffer Overflow
Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5148?
CVE-2014-5148 is considered a high severity vulnerability due to the potential for local guest users to exploit the issue.
How do I fix CVE-2014-5148?
To fix CVE-2014-5148, you should upgrade Xen to version 4.4.2 or later which contains the necessary patches.
What versions of Xen are affected by CVE-2014-5148?
CVE-2014-5148 affects Xen versions 4.4.0 and 4.4.1.
What type of systems are impacted by CVE-2014-5148?
CVE-2014-5148 impacts ARM systems running Xen hypervisor.
What is the nature of the vulnerability in CVE-2014-5148?
CVE-2014-5148 allows local guest users to access kernel space due to improper handling of unknown system register accesses.