CVE-2014-7155: Debian Linux
Medium severity, CVSS 5.8. EPSS: 1% chance of exploitation in the next 30 days.
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
Affected products
- Debian Debian Linux: version 7.0 only
- Fedoraproject Fedora: version 19 only; version 20 only
- Opensuse Opensuse: version 12.3 only; version 13.1 only
- Xen Xen: up to and including 4.4.0; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.1.3 only; version 3.1.4 only; …
Published 2014-10-02. Last modified 2026-06-17.