CVE-2014-9030: Input Validation
The dommuupdate function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMUMACHPHYSUPDATE.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9030?
CVE-2014-9030 has been classified as a medium severity vulnerability that can lead to denial of service.
How do I fix CVE-2014-9030?
To fix CVE-2014-9030, it is recommended to upgrade to a patched version of Xen, specifically versions 4.4.1 or higher.
What systems are affected by CVE-2014-9030?
CVE-2014-9030 affects Xen versions from 3.2.0 through 4.4.0, including various HVM guests.
What type of attack can exploit CVE-2014-9030?
CVE-2014-9030 can be exploited by remote domains to perform a denial of service attack leveraging control over an HVM guest.
Is there a workaround for CVE-2014-9030?
There are no known workarounds for CVE-2014-9030; upgrading to a secure version is the only mitigation.