LOW · 1.9

CVE-2014-8595

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a craft...

Vulnerability Description

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.

CVSS Score

1.9

LOW

AV:L/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
DebianDebian Linux7.0
XenXen3.2.1
OpensuseOpensuse13.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8595?

CVE-2014-8595 is a vulnerability with a CVSS score of 1.9 (LOW). arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a craft...

How severe is CVE-2014-8595?

CVE-2014-8595 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8595?

Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Xen Xen, Opensuse Opensuse.