PT-2013-6341 · Linux+3 · Linux Kernel+7

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2014-0155

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.14.1 SUSE Linux Enterprise kernel-pae-devel (affected versions not specified) SUSE Linux Enterprise kernel-xen-devel (affected versions not specified) SUSE Linux Enterprise gfs2-kmp-xen (affected versions not specified) SUSE Linux Enterprise kernel-ec2-devel (affected versions not specified)
Description The issue allows guest OS users to cause a denial of service (host OS crash) via a crafted entry in the redirection table of an I/O APIC. This is due to the ioapic deliver function in virt/kvm/ioapic.c not properly validating the kvm irq delivery to apic return value. The affected code was moved to the ioapic service function before the vulnerability was announced. Multiple vulnerabilities in SUSE Linux Enterprise packages may lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For Linux kernel versions through 3.14.1: Update to a version later than 3.14.1 to resolve the issue. For SUSE Linux Enterprise kernel-pae-devel: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For SUSE Linux Enterprise kernel-xen-devel: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For SUSE Linux Enterprise gfs2-kmp-xen: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For SUSE Linux Enterprise kernel-ec2-devel: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1547
ALT-PU-2014-1602
ALT-PU-2014-1617
ALT-PU-2014-1632
ALT-PU-2014-1633
ALT-PU-2014-2064
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CVE-2014-0155
MGASA-2014-0225
MGASA-2014-0226
MGASA-2014-0227
MGASA-2014-0228
MGASA-2014-0229
MGASA-2014-0234
MGASA-2014-0235
MGASA-2014-0236
MGASA-2014-0237
MGASA-2014-0238
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2239-1
USN-2241-1
USN-2336-1
USN-2337-1

Affected Products

Alt Linux
Linux Kernel
Suse Linux Enterprise Gfs2-Kmp-Xen
Suse Linux Enterprise Kernel-Ec2-Devel
Suse Linux Enterprise Kernel-Pae-Devel
Suse Linux Enterprise Kernel-Xen-Devel
Suse
Ubuntu