Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9065
HistoryDec 09, 2014 - 12:00 a.m.

CVE-2014-9065

2014-12-0900:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.001

Percentile

26.7%

common/spinlock.c in Xen 4.4.x and earlier does not properly handle read
and write locks, which allows local x86 guest users to cause a denial of
service (write denial or NMI watchdog timeout and host crash) via a large
number of read requests, a different vulnerability to CVE-2014-9066.

Notes

Author Note
mdeslaur doesn’t affect 4.1
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchxen< 4.4.1-0ubuntu0.14.04.4UNKNOWN
ubuntu14.10noarchxen< 4.4.1-0ubuntu0.14.10.4UNKNOWN

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.001

Percentile

26.7%