CVE-2014-7156: Low severity xen xapi vulnerability
The x86emulate function in arch/x86/x86emulate/x86emulate.c in Xen 3.3.x through 4.4.x does not check the supervisor mode permissions for instructions that generate software interrupts, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7156?
CVE-2014-7156 is classified as a denial of service vulnerability that allows guest crashes due to insufficient permission checks.
How do I fix CVE-2014-7156?
To fix CVE-2014-7156, you should update your Xen hypervisor to a version that has addressed this vulnerability.
Which versions of Xen are affected by CVE-2014-7156?
CVE-2014-7156 affects Xen versions from 3.3.0 through 4.4.1.
Can CVE-2014-7156 be exploited remotely?
CVE-2014-7156 requires local access to the HVM guest, so it cannot be exploited remotely.
What type of issues does CVE-2014-7156 cause?
CVE-2014-7156 can lead to denial of service situations where the guest operating system crashes.