PT-2014-1009 · Linux+1 · Linux Kernel+1

Published

2014-03-04

·

Updated

2023-02-13

·

CVE-2014-0049

CVSS v2.0

7.4

High

VectorAV:A/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.13.6
Description The issue is related to a buffer overflow in the complete emulated mmio function, which allows guest OS users to execute arbitrary code on the host OS. This is achieved by leveraging a loop that triggers an invalid memory copy affecting certain cancel work item data.
Recommendations For Linux kernel versions prior to 3.13.6, update to version 3.13.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the complete emulated mmio function to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1258
ALT-PU-2014-1272
ALT-PU-2014-1547
ALT-PU-2014-2064
BDU:2014-00055
CVE-2014-0049
MGASA-2014-0206
MGASA-2014-0207
MGASA-2014-0208
MGASA-2014-0228
MGASA-2014-0229
MGASA-2014-0234
MGASA-2014-0235
MGASA-2014-0236
MGASA-2014-0237
MGASA-2014-0238
USN-2175-1
USN-2176-1
USN-2177-1
USN-2178-1
USN-2179-1
USN-2180-1
USN-2181-1

Affected Products

Alt Linux
Linux Kernel