CVE-2014-8595
EPSS 0.07%
Description
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.
How to fix CVE-2014-8595
To remediate CVE-2014-8595, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.4.1-4 or later
Is CVE-2014-8595 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.4.1-4