Xen 3.3 through 4.1, when XSM is enabled, allows local users to cause a denial of service via vectors related to a "large memory allocation," a different vulnerability than CVE-2014-1891, CVE-2014-1893, and CVE-2014-1894.
CVSS Details
- CVSS 3.1 Base Score: 5.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-emulations/xen.Upgrade app-emulations/xen-pvgrub.Upgrade app-emulations/xen-tools. | Oct 30, 2017 | Apr 1, 2014 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-toolsUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-doc-htmlUpgrade xen-kmp-traceUpgrade xenUpgrade xen-doc-pdfUpgrade xen-develUpgrade xen-tools-domUUpgrade xen-libs | Dec 18, 2015 | Mar 14, 2014 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub