Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8867

Опубликовано: 27 нояб. 2014
Источник: redhat
CVSS2: 5.2
EPSS Низкий

Описание

The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.

An insufficient bound checking flaw was found in the Xen hypervisor's implementation of acceleration support for the "REP MOVS" instructions. A privileged HVM guest user could potentially use this flaw to crash the host.

Отчет

This issue does affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5. Future kernel-xen updates for Red Hat Enterprise Linux 5 may address this issue.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1164255xen: Insufficient bounding of "REP MOVS" to MMIO emulated inside the hypervisor (xsa112)

EPSS

Процентиль: 33%
0.00126
Низкий

5.2 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.

nvd
больше 10 лет назад

The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.

debian
больше 10 лет назад

The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, ...

github
около 3 лет назад

The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.

oracle-oval
около 10 лет назад

ELSA-2015-0783: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 33%
0.00126
Низкий

5.2 Medium

CVSS2