cbcvebase.
CVE-2014-0155
published 2014-04-14

CVE-2014-0155: The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which…

PriorityP422medium5.5CVSS 2.0
AVAACLAuSCNINAC
EPSS
0.98%
58.9th percentile
The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which allows guest OS users to cause a denial of service (host OS crash) via a crafted entry in the redirection table of an I/O APIC. NOTE: the affected code was moved to the ioapic_service function before the vulnerability was announced.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.14.4-1 (bookworm)linux 3.14.4-1 (bookworm)
linuxlinux_kernel< 3.14.13.14.1
linuxlinux_kernel>= 0 < 3.14.4-13.14.4-1
linuxlinux_kernel>= 0 < 3.14.4-13.14.4-1
linuxlinux_kernel>= 0 < 3.14.4-13.14.4-1
linuxlinux_kernel>= 0 < 3.14.4-13.14.4-1
linuxlinux_kernel>= 0 < 3.13.0-35.623.13.0-35.62

CVSS provenance

nvdv2.05.5MEDIUMAV:A/AC:L/Au:S/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.