PT-2014-5413 · Linux+5 · Linux Kernel+5

Jack Morgenstein

·

Publicado

2014-08-31

·

Atualizado

2023-02-13

·

CVE-2014-3601

CVSS v2.0

4.3

Média

VetorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.16.1
Description The issue arises from a miscalculation in the number of pages during the handling of a mapping failure in the kvm iommu map pages function. This allows guest OS users to cause a denial of service, either through host OS memory corruption by triggering a large gfn value or through host OS memory consumption by triggering a small gfn value, leading to permanently pinned pages.
Recommendations For Linux kernel versions prior to 3.16.1, update to version 3.16.1 or later to resolve the issue.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2106
ALT-PU-2015-1794
CESA-2014_1392
CVE-2014-3601
MGASA-2014-0392
MGASA-2014-0451
MGASA-2014-0452
MGASA-2014-0453
MGASA-2014-0454
MGASA-2014-0455
MGASA-2014-0456
MGASA-2014-0459
MGASA-2014-0479
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
RHSA-2014:1392
RHSA-2014_1392
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2356-1
USN-2357-1
USN-2358-1
USN-2359-1

Produtos afetados

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu