PT-2015-4535 · Linux+4 · Linux Kernel+4

Nadav Amit

·

Published

2015-01-23

·

Updated

2023-02-13

·

CVE-2015-0239

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.18.5
Description The issue allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction, specifically when the guest OS lacks SYSENTER MSR initialization. This occurs due to a problem in the em sysenter function in arch/x86/kvm/emulate.c.
Recommendations For Linux kernel versions prior to 3.18.5, update to version 3.18.5 or later to resolve the issue.

Exploit

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1118
ALT-PU-2015-1794
CESA-2015_1272
CESA-2015_2152
CVE-2015-0239
DSA-3170-1
MGASA-2015-0210
MGASA-2015-0219
MGASA-2015-0221
RHSA-2015:1272
RHSA-2015:2152
RHSA-2015_1272
RHSA-2015_2152
USN-2513-1
USN-2514-1
USN-2515-1
USN-2516-1
USN-2516-2
USN-2516-3
USN-2517-1
USN-2518-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu