PT-2014-1935 · Linux+4 · Linux Kernel+4

Published

2014-12-31

·

Updated

2024-06-06

·

CVE-2014-8159

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux kernel package versions prior to 2.6.32-504.12.2 Red Hat Enterprise Linux kernel-tools-libs-devel (affected versions not specified) Red Hat Enterprise Linux kernel-tools (affected versions not specified) Red Hat Enterprise Linux kernel-devel (affected versions not specified) Red Hat Enterprise Linux kernel-doc (affected versions not specified) Red Hat Enterprise Linux kernel-headers (affected versions not specified) Red Hat Enterprise Linux kernel-debug (affected versions not specified) Red Hat Enterprise Linux kernel-abi-whitelists (affected versions not specified) Red Hat Enterprise Linux kernel-kdump-devel (affected versions not specified) Red Hat Enterprise Linux kernel-bootwrapper (affected versions not specified) Red Hat Enterprise Linux kernel-kdump (affected versions not specified) Red Hat Enterprise Linux kernel-debug-devel (affected versions not specified) Red Hat Enterprise Linux kernel-tools-libs (affected versions not specified) Red Hat Enterprise Linux perf (affected versions not specified) Red Hat Enterprise Linux kernel (affected versions not specified)
Description The issue affects the Linux kernel package in Red Hat Enterprise Linux, allowing local users to access arbitrary physical memory locations and potentially cause a denial of service or gain privileges. The vulnerability can be exploited remotely. The InfiniBand implementation does not properly restrict the use of User Verbs for registration of memory regions, allowing users to leverage permissions on a uverbs device under /dev/infiniband/.
Recommendations For Red Hat Enterprise Linux kernel package versions prior to 2.6.32-504.12.2, update to version 2.6.32-504.12.2 or later. For other affected packages, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09825
BDU:2015-09826
BDU:2015-09827
BDU:2015-09828
BDU:2015-09829
BDU:2015-09830
BDU:2015-09831
BDU:2015-09832
BDU:2015-09833
BDU:2015-09834
BDU:2015-09835
BDU:2015-09836
BDU:2015-09837
BDU:2015-09838
CESA-2015_0674
CESA-2015_0726
CVE-2014-8159
DLA-246-1
DSA-3237-1
MGASA-2015-0171
MGASA-2015-0172
MGASA-2015-0219
RHSA-2015:0674
RHSA-2015:0695
RHSA-2015:0726
RHSA-2015:0727
RHSA-2015:0751
RHSA-2015:0782
RHSA-2015:0783
RHSA-2015:0803
RHSA-2015:0870
RHSA-2015:0919
RHSA-2015_0674
RHSA-2015_0726
RHSA-2015_0727
RHSA-2015_0783
SUSE-RU-2015:0621-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1071-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
SUSE-SU-2015:1478-1
SUSE-SU-2015:1487-1
SUSE-SU-2015:1488-1
SUSE-SU-2015:1489-1
SUSE-SU-2015:1491-1
USN-2525-1
USN-2526-1
USN-2527-1
USN-2528-1
USN-2529-1
USN-2530-1
USN-2561-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse
Ubuntu