CVE-2014-2580: Xen

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which causes a mutex to be taken when trying to disable the interface.

Affected products

  • Xen Xen: affected versions not specified

Published 2014-04-15. Last modified 2026-06-17.