CVE-2014-5149
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page…
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
- CVSS 2.0
- 4.7 MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- opensuse/opensuse · xen/xen
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136980.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136981.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlThird Party Advisory
- http://www.securityfocus.com/bid/69199Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030723Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-97.htmlPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95235
- https://security.gentoo.org/glsa/201504-04
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136980.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136981.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00010.htmlThird Party Advisory
- http://www.securityfocus.com/bid/69199Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030723Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-97.htmlPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95235
- https://security.gentoo.org/glsa/201504-04
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.