SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3714

The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer…

LOW 3.3EPSS 0.41%

Does this matter?

Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.

Description

The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.

CVSS 2.0
3.3 LOWAV:L/AC:M/Au:N/C:P/I:N/A:P
EPSS
0.41% probability · 35th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
xen/xen
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.