CVE-2014-8595

low
Published 2014-11-19 · Modified 2026-05-06
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-8595

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://xenbits.xen.org/xsa/advisory-110.html

OS impact

OSVersionStatusFixed in
suse suse13.1affected
suse suse13.2affected
debian debian7.0affected
debian debianbookwormfixed4.4.1-4
debian debianbullseyefixed4.4.1-4
debian debianforkyfixed4.4.1-4
debian debiansidfixed4.4.1-4
debian debiantrixiefixed4.4.1-4

References

CWEs

CWE-17

Verify integrity in audit chain (admin only). AS-IS.