CVE-2014-3125
Published: 2 May 2014
Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the hardware timers and cause a denial of service (crash) via unspecified vectors.
Notes
Author | Note |
---|---|
mdeslaur | 32- and 64-bit ARM systems only, 4.4.x only |
Priority
Status
Package | Release | Status |
---|---|---|
xen Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
|
|
saucy |
Not vulnerable
|
|
trusty |
Released
(4.4.0-0ubuntu5.1)
|
|
upstream |
Needs triage
|
|
Binaries built from this source package are in Universe and so are supported by the community. | ||
xen-3.3 Launchpad, Ubuntu, Debian |
lucid |
Not vulnerable
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
saucy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
Binaries built from this source package are in Universe and so are supported by the community. |
References
- http://xenbits.xen.org/xsa/advisory-91.html
- http://www.securitytracker.com/id/1030184
- http://www.openwall.com/lists/oss-security/2014/04/30/5
- http://www.openwall.com/lists/oss-security/2014/04/30/11
- http://secunia.com/advisories/58347
- https://www.cve.org/CVERecord?id=CVE-2014-3125
- NVD
- Launchpad
- Debian