ALT-PU-2014-1545-1
Closed vulnerabilities
Published: 2014-04-24
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2014-2915
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.
Severity: MEDIUM (5.5)
References:
- [oss-security] 20140422 Re: Xen Security Advisory 93 - Hardware features unintentionally exposed to guests on ARM
- [oss-security] 20140422 Re: Xen Security Advisory 93 - Hardware features unintentionally exposed to guests on ARM
- [oss-security] 20140423 Xen Security Advisory 93 (CVE-2014-2915) - Hardware features unintentionally exposed to guests on ARM
- [oss-security] 20140423 Xen Security Advisory 93 (CVE-2014-2915) - Hardware features unintentionally exposed to guests on ARM
- 1030135
- 1030135
- http://xenbits.xen.org/xsa/advisory-93.html
- http://xenbits.xen.org/xsa/advisory-93.html
Published: 2014-04-28
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2014-2986
The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.
Severity: MEDIUM (5.5)
References:
- [oss-security] 20140423 Xen Security Advisory 94 - ARM hypervisor crash on guest interrupt controller access
- [oss-security] 20140423 Xen Security Advisory 94 - ARM hypervisor crash on guest interrupt controller access
- [oss-security] 20140423 Re: Xen Security Advisory 94 - ARM hypervisor crash on guest interrupt controller access
- [oss-security] 20140423 Re: Xen Security Advisory 94 - ARM hypervisor crash on guest interrupt controller access
- [oss-security] 20140423 Xen Security Advisory 94 (CVE-2014-2986) - ARM hypervisor crash on guest interrupt controller access
- [oss-security] 20140423 Xen Security Advisory 94 (CVE-2014-2986) - ARM hypervisor crash on guest interrupt controller access
- 67047
- 67047
- 1030146
- 1030146
- http://xenbits.xen.org/xsa/advisory-94.html
- http://xenbits.xen.org/xsa/advisory-94.html