← Back

CVE-2014-1895

nvd nist
Published: Apr 1, 2014Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:A/AC:M/Au:S/C:P/I:N/A:C
Exploitability: 4.4 / Impact: 7.8
Source: NVD

Description

Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.

Affected (6)

Products: Xen: Xen
1 product
Xen
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Xen
Version 4.2.0
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.3.0
Version 4.3.1

Related CWEs

References (10)

Timeline

No history available yet.