CVE-2014-5149: Medium severity opensuse vulnerability
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5149?
CVE-2014-5149 has a severity rating that indicates it can lead to denial of service due to excessive vcpu consumption.
How do I fix CVE-2014-5149?
To fix CVE-2014-5149, upgrade to a patched version of Xen that addresses this vulnerability.
Which versions of Xen are affected by CVE-2014-5149?
CVE-2014-5149 affects Xen versions 4.2.x through 4.4.x when utilizing shadow pagetables.
What type of attack is possible with CVE-2014-5149?
CVE-2014-5149 allows local HVM guests to execute operations that can cause denial of service by monopolizing CPU resources.
Is CVE-2014-5149 specific to certain operating systems?
Yes, CVE-2014-5149 impacts specific distributions of OpenSUSE such as 13.1 and 13.2, along with certain versions of Xen.