CVE-2014-4021
EPSS 0.23%
Description
Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors.
How to fix CVE-2014-4021
To remediate CVE-2014-4021, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.4.1-1 or later
Is CVE-2014-4021 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.4.1-1