Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlier, when XSM is enabled, allow local users to cause a denial of service (processor fault) via unspecified vectors, a different vulnerability than CVE-2014-1891, CVE-2014-1892, and CVE-2014-1894.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-emulations/xen-tools.Upgrade app-emulations/xen.Upgrade app-emulations/xen-pvgrub. | Oct 30, 2017 | Apr 1, 2014 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-tools-domUUpgrade xen-libs-32bitUpgrade xen-kmp-traceUpgrade xenUpgrade xen-kmp-defaultUpgrade xen-doc-pdfUpgrade xen-doc-htmlUpgrade xen-toolsUpgrade xen-libsUpgrade xen-devel | Dec 18, 2015 | Mar 14, 2014 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub