The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via vectors involving an uninitialized FIFO-based event channel control block when (1) binding or (2) moving an event to a different VCPU.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6268
Reference (s):
- BID:69753
- URL: http://www.securityfocus.com/bid/69753
- http://xenbits.xen.org/xsa/advisory-107.html
- SECTRACK:1030829
- URL: http://www.securitytracker.com/id/1030829

