PT-2014-5413 · Linux+5 · Linux Kernel+5

Jack Morgenstein

·

Published

2014-08-31

·

Updated

2023-02-13

·

CVE-2014-3601

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.16.1
Description The issue arises from a miscalculation in the number of pages during the handling of a mapping failure in the kvm iommu map pages function. This allows guest OS users to cause a denial of service, either through host OS memory corruption by triggering a large gfn value or through host OS memory consumption by triggering a small gfn value, leading to permanently pinned pages.
Recommendations For Linux kernel versions prior to 3.16.1, update to version 3.16.1 or later to resolve the issue.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2106
ALT-PU-2015-1794
CESA-2014_1392
CVE-2014-3601
MGASA-2014-0392
MGASA-2014-0451
MGASA-2014-0452
MGASA-2014-0453
MGASA-2014-0454
MGASA-2014-0455
MGASA-2014-0456
MGASA-2014-0459
MGASA-2014-0479
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
RHSA-2014:1392
RHSA-2014_1392
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2356-1
USN-2357-1
USN-2358-1
USN-2359-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu