AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-1895

MEDIUM · CVSS 5.8 EPSS 0.53%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-04-01 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-1895
Severity
MEDIUM
CVSS
5.8
EPSS
0.53%

Original Filing — NVD Description

Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.