CVE-2014-3714: Xen

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.

Affected products

  • Xen Xen: version 4.4.0 only

Published 2014-05-19. Last modified 2026-06-17.