4.3

CVE-2014-3601

Exploit

The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SuseLinux Enterprise Real Time Extension Version11.0 Updatesp3
OpensuseEvergreen Version11.4
SuseLinux Enterprise Server Version11 Updatesp2 SwEditionltss
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
LinuxLinux Kernel Version <= 3.16.1
LinuxLinux Kernel Version3.16.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.579
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.5 6.9
AV:A/AC:H/Au:S/C:N/I:N/A:C