CVE-2014-7188: High severity xen xapi vulnerability
The hvmmsrreadintercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7188?
CVE-2014-7188 is categorized with a moderate severity level due to its ability to cause denial of service and potential information disclosure.
How do I fix CVE-2014-7188?
To mitigate CVE-2014-7188, upgrade to Xen version 4.4.2 or later, which contains the necessary patches.
What are the impacts of CVE-2014-7188?
CVE-2014-7188 can lead to host crashes and unauthorized data access between local HVM guests.
Which versions of Xen are affected by CVE-2014-7188?
CVE-2014-7188 affects Xen versions from 4.1.0 up to and including 4.4.1.
Is my hypervisor secure if I use a vulnerable version related to CVE-2014-7188?
Using a vulnerable version of Xen related to CVE-2014-7188 exposes your hypervisor to denial of service and potential data leakage risks.