CVE-2014-2580
Last modified
CVE-2014-2580 is a vulnerability of currently unknown severity. The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which causes a mutex to be taken when trying to disable the interface.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which causes a mutex to be taken when trying to disable the interface.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | All versions |
References
- http://xenbits.xen.org/xsa/advisory-90.htmlPatch, Vendor Advisory
- http://xenbits.xen.org/xsa/advisory-90.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2580?
How severe is CVE-2014-2580?
How do I fix CVE-2014-2580?
Are you affected by CVE-2014-2580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
