Date published: 2014-05-19T10:55:12.377-04:00
Date last modified: 2016-10-19T13:03:55.533-04:00
CVSS Score: 3.3
Principal attack vector: LOCAL
Reference URL: http://www.openwall.com/lists/oss-security/2014/05/14/4
Summary: The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.