CVE-2014-8866
EPSS 0.09%
Description
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.
How to fix CVE-2014-8866
To remediate CVE-2014-8866, upgrade the affected package to a fixed version below.
- Debian/xen—upgrade to 4.4.1-5 or later
Is CVE-2014-8866 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.4.1-5