CVE-2014-1895

Source
https://cve.org/CVERecord?id=CVE-2014-1895
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-1895.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2014-1895
Downstream
Published
2014-04-01T06:35:53Z
Modified
2026-04-10T03:43:38Z
Summary
[none]
Details

Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.

References

Affected packages