6.9

CVE-2014-8159

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 2.6.12 < 3.2.69
LinuxLinux Kernel Version >= 3.3 < 3.4.108
LinuxLinux Kernel Version >= 3.5 < 3.10.75
LinuxLinux Kernel Version >= 3.11 < 3.12.41
LinuxLinux Kernel Version >= 3.13 < 3.14.39
LinuxLinux Kernel Version >= 3.15 < 3.16.35
LinuxLinux Kernel Version >= 3.17 < 3.18.13
LinuxLinux Kernel Version >= 3.19 < 3.19.5
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version14.10
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.236
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
http://www.securityfocus.com/bid/73060
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032224
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1181166
Third Party Advisory
Issue Tracking