CVE-2014-5149: Opensuse
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.
Affected products
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Xen Xen: version 4.2.0 only; version 4.2.1 only; version 4.2.2 only; version 4.2.3 only; version 4.3.0 only; version 4.3.1 only; …
Published 2014-08-22. Last modified 2026-06-17.