CVE-2014-9066
EPSS 0.11%
Description
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
How to fix CVE-2014-9066
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/xen—no fix listed
Is CVE-2014-9066 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0