Back to search
CVE-2014-1950
Published: Feb 14, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2014:0373
vendor-advisory
x_refsource_SUSE
SUSE-SU-2014:0372
vendor-advisory
x_refsource_SUSE
http://xenbits.xen.org/xsa/advisory-88.html
x_refsource_CONFIRM
DSA-3006
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now