5.5

CVE-2014-3690

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls within a modified copy of QEMU.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 3.17.2
Novell ≫ Suse Linux Enterprise Desktop Version 12.0 Update -
Novell ≫ Suse Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Novell ≫ Suse Linux Enterprise Server Version 12.0 Update -
Opensuse ≫ Evergreen Version 11.4
Suse ≫ Linux Enterprise Real Time Extension Version 11 Update sp3
Redhat ≫ Enterprise Linux Version 5.0
Debian ≫ Debian Linux Version 7.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.396
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-0782.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-0864.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0290.html
Third Party Advisory
http://secunia.com/advisories/60174
Broken Link
http://www.ubuntu.com/usn/USN-2417-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2418-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2419-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2420-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2421-1
Third Party Advisory
http://www.debian.org/security/2014/dsa-3060
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00035.html
Third Party Advisory
Mailing List
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d974baa398f34393db76be45f7d4d04fbdbb4a0a
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.2
Patch
Vendor Advisory
Mailing List
http://www.mandriva.com/security/advisories?name=MDVSA-2015:058
Broken Link
http://www.openwall.com/lists/oss-security/2014/10/21/4
Patch
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2014/10/29/7
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/70691
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1153322
Patch
Third Party Advisory
Issue Tracking
https://github.com/torvalds/linux/commit/d974baa398f34393db76be45f7d4d04fbdbb4a0a
Patch
Third Party Advisory