VDB
CVE-2014-1642
CVE-2014-1642
PUBLISHED
CVSS 4.400000095367432 MEDIUM
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.
EPSS 0.18% · 39.2th percentile
Risk Scores
CVSS 2.0
4.400000095367432
EPSS Score
0.18%
39.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| xen | xen | 4.2.0, 4.2.1, 4.2.2 |
Timeline
- Jan 26, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- SUSE-SU-2014:0373 vendor-advisory
- FEDORA-2014-1552 vendor-advisory
- xen-irq-cve20141642-code-exec(90649) vdb
- 56557 third-party-advisory
- GLSA-201407-03 vendor-advisory
- FEDORA-2014-1559 vendor-advisory
- [oss-security] 20140123 Xen Security Advisory 83 (CVE-2014-1642) - Out-of-memory condition yielding memory corruption during IRQ setup mailing-list
- 102406 vdb
- 1029679 vdb
- 65097 vdb
- http://xenbits.xen.org/xsa/advisory-83.html url
- http://lists.xen.org/archives/html/xen-announce/2014-01/msg00001.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-1642 advisory