Upstream information

CVE-2014-3125 at MITRE


Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the hardware timers and cause a denial of service (crash) via unspecified vectors.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.2
Vector AV:A/AC:L/Au:S/C:N/I:P/A:C
Access Vector Adjacent Network
Access Complexity Low
Authentication Single
Confidentiality Impact None
Integrity Impact Partial
Availability Impact Complete
SUSE Bugzilla entry: 873992 [RESOLVED / WONTFIX]

No SUSE Security Announcements cross referenced.