3.3

CVE-2014-8134

Exploit

The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 3.18
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
OpensuseEvergreen Version11.4
OpensuseOpensuse Version13.1
SuseSuse Linux Enterprise Server Version11 Updatesp2 SwEditionltss
OracleLinux Version6 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.236
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N
http://www.securityfocus.com/bid/71650
Third Party Advisory
VDB Entry
http://www.spinics.net/lists/kvm/msg111458.html
Patch
Third Party Advisory
Exploit
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1172765
Patch
Third Party Advisory
Issue Tracking