CVE-2014-2915

Publication date 24 April 2014

Last updated 24 July 2024


Ubuntu priority

Description

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.

Read the notes from the security team

Status

Package Ubuntu Release Status
xen 14.04 LTS trusty
Fixed 4.4.0-0ubuntu5.1
13.10 saucy
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release
xen-3.3 14.04 LTS trusty Not in release
13.10 saucy Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid
Not affected

Notes


seth-arnold

Only affects ARM 32 bit, ARM 64 bit, 4.4 and newer. Only "medium" because advisory indicates privilege escalation is not thought possible


Access our resources on patching vulnerabilities