Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID suboperations in the flask hypercall in Xen 4.3.x, 4.2.x, 4.1.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1892, CVE-2014-1893, and CVE-2014-1894.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-emulations/xen-tools.Upgrade app-emulations/xen-pvgrub.Upgrade app-emulations/xen. | Oct 30, 2017 | Apr 1, 2014 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-kmp-traceUpgrade xenUpgrade xen-tools-domUUpgrade xen-doc-htmlUpgrade xen-develUpgrade xen-libsUpgrade xen-toolsUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-doc-pdf | Dec 18, 2015 | Mar 14, 2014 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub