The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188
Reference (s):
- BID:70198
- URL: http://www.securityfocus.com/bid/70198
- http://support.citrix.com/article/CTX200218
- http://support.citrix.com/article/CTX201794
- http://xenbits.xen.org/xsa/advisory-108.html

