SB2015012307 - Input validation error in xen (Alpine package)
Published: January 23, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2014-9065)
The vulnerability allows a local #AU# to perform a denial of service (DoS) attack.
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
Remediation
Install update from vendor's website.