CVE-2014-8595: Low severity debian linux vulnerability
arch/x86/x86emulate/x86emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8595?
The severity of CVE-2014-8595 is classified as high due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2014-8595?
To fix CVE-2014-8595, you should upgrade to a version of Xen later than 4.4.x or apply security patches provided by your operating system vendor.
What types of systems are affected by CVE-2014-8595?
CVE-2014-8595 affects various versions of Xen hypervisor, specifically versions from 3.2.1 up to 4.4.x.
Can CVE-2014-8595 lead to denial of service?
Yes, CVE-2014-8595 can cause a denial of service by allowing a local HVM guest user to crash the system.
Is it safe to continue using affected Xen versions with CVE-2014-8595?
It is not safe to continue using affected Xen versions as they expose systems to potential privilege escalation and denial of service attacks.