Vulnerability Database

290,278

Total vulnerabilities in the database

CVE-2014-4022

The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOP_setup_table subhypercall.

  • Published: Jul 9, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-4022
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 2.7
  • AV:A/AC:L/Au:S/C:P/I:N/A:N

CWEs: