CVE-2014-7188

high
Published 2014-10-02 · Modified 2026-05-06
CVSS v3
CVSS v2
8.3
VIR risk
8.3

Description

The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-7188

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://xenbits.xen.org/xsa/advisory-108.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.4.1-3
debian debianbullseyefixed4.4.1-3
debian debianforkyfixed4.4.1-3
debian debiansidfixed4.4.1-3
debian debiantrixiefixed4.4.1-3

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.