CVE-2014-6268: Xen

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via vectors involving an uninitialized FIFO-based event channel control block when (1) binding or (2) moving an event to a different VCPU.

Affected products

  • Xen Xen: version 4.4.0 only; version 4.4.1 only

Published 2015-01-12. Last modified 2026-06-17.