Vulnerability CVE-2014-3601


Published: 2014-08-31   Modified: 2014-09-01

Description:
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.

Type:

CWE-189

(Numeric Errors)

CVSS2 => (AV:A/AC:H/Au:S/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
6.9/10
2.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
High
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
SUSE -> Linux enterprise real time extension 
SUSE -> Linux enterprise server 
SUSE -> Suse linux enterprise server 
Opensuse -> Evergreen 
Linux -> Linux kernel 
Canonical -> Ubuntu linux 

 References:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
http://secunia.com/advisories/60830
http://www.securityfocus.com/bid/69489
http://www.ubuntu.com/usn/USN-2356-1
http://www.ubuntu.com/usn/USN-2357-1
http://www.ubuntu.com/usn/USN-2358-1
http://www.ubuntu.com/usn/USN-2359-1
https://bugzilla.redhat.com/show_bug.cgi?id=1131951
https://exchange.xforce.ibmcloud.com/vulnerabilities/95689
https://github.com/torvalds/linux/commit/350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7

Copyright 2024, cxsecurity.com

 

Back to Top