CVE-2014-3601
published 2014-09-01CVE-2014-3601: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping…
PriorityP419medium4.3CVSS 2.0
AVAACHAuSCNINAC
EPSS
1.17%
64.1th percentile
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt2-1 (bookworm) | linux 3.16.7-ckt2-1 (bookworm) |
| debian | linux | < linux 3.16.2-1 (bookworm) | linux 3.16.2-1 (bookworm) |
| linux | linux_kernel | <= 3.16.1 | — |
| linux | linux_kernel | <= 3.17.2 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-36.63 | 3.13.0-36.63 |
| opensuse | evergreen | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:A/AC:H/Au:S/C:N/I:N/A:C
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path
vendor_redhat·2014-10-24·CVSS 4.3
CVE-2014-8369 [MEDIUM] kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path
kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.
It was found that the fix for CVE-2014-3601 was incomplete: the Linux kernel's kvm_iommu_map_pages() function still handled IOMMU mapping failures incorrectly. A privileged user in a guest with an assigned host device could use this flaw to crash the host.
Statement: This issue did not affect the Linux kernel versions as ship
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-09-23·CVSS 4.3
CVE-2014-3601 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jack Morgenstein reported a flaw in the page handling of the KVM (Kerenl
Virtual Machine) subsystem in the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service (host OS memory corruption)
or possibly have other unspecified impact on the host OS. (CVE-2014-3601)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mount a custom
iso9660 image either via a CD/DVD drive or a loopback
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-23·CVSS 4.3
CVE-2014-3601 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jack Morgenstein reported a flaw in the page handling of the KVM (Kerenl
Virtual Machine) subsystem in the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service (host OS memory corruption)
or possibly have other unspecified impact on the host OS. (CVE-2014-3601)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mount a custom
iso9660 image either via a CD/DVD drive or a loopback mount could c
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-23·CVSS 4.3
CVE-2014-3601 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jack Morgenstein reported a flaw in the page handling of the KVM (Kerenl
Virtual Machine) subsystem in the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service (host OS memory corruption)
or possibly have other unspecified impact on the host OS. (CVE-2014-3601)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mount a custom
iso9660 image either via a CD/DVD drive or a loopback mount could cause a
denial of service (system crash or reboot). (CVE-2014-5471)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mount a cu
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-09-23·CVSS 4.3
CVE-2014-3601 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jack Morgenstein reported a flaw in the page handling of the KVM (Kerenl
Virtual Machine) subsystem in the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service (host OS memory corruption)
or possibly have other unspecified impact on the host OS. (CVE-2014-3601)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mount a custom
iso9660 image either via a CD/DVD drive or a loopback mount could cause a
denial of service (system crash or reboot). (CVE-2014-5471)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mo
Red Hat
kernel: kvm: invalid parameter passing in kvm_iommu_map_pages()
vendor_redhat·2014-08-19·CVSS 4.3
CVE-2014-3601 [MEDIUM] kernel: kvm: invalid parameter passing in kvm_iommu_map_pages()
kernel: kvm: invalid parameter passing in kvm_iommu_map_pages()
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
A flaw was found in the way the Linux kernel's kvm_iommu_map_pages() function handled IOMMU mapping failures. A privileged user in a guest with an assigned host device could use this flaw to crash the host.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Pack
Debian
CVE-2014-8369: linux - The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through...
vendor_debian·2014·CVSS 4.3
CVE-2014-8369 [MEDIUM] CVE-2014-8369: linux - The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through...
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1)
sid: resolved (fixed in 3.16.7-ckt2-1)
trixie: resolved (fixed in 3.16.7-ckt2-1)
Debian
CVE-2014-3601: linux - The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through...
vendor_debian·2014·CVSS 4.3
CVE-2014-3601 [MEDIUM] CVE-2014-3601: linux - The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through...
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
Scope: local
bookworm: resolved (fixed in 3.16.2-1)
bullseye: resolved (fixed in 3.16.2-1)
forky: resolved (fixed in 3.16.2-1)
sid: resolved (fixed in 3.16.2-1)
trixie: resolved (fixed in 3.16.2-1)
GHSA
GHSA-58c4-c7v3-ccxc: The kvm_iommu_map_pages function in virt/kvm/iommu
ghsa_unreviewed·2022-05-14
CVE-2014-3601 [MEDIUM] GHSA-58c4-c7v3-ccxc: The kvm_iommu_map_pages function in virt/kvm/iommu
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
GHSA
GHSA-78qf-3xpg-qfgr: The kvm_iommu_map_pages function in virt/kvm/iommu
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2014-8369 [MEDIUM] CWE-119 GHSA-78qf-3xpg-qfgr: The kvm_iommu_map_pages function in virt/kvm/iommu
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.
OSV
CVE-2014-8369: The kvm_iommu_map_pages function in virt/kvm/iommu
osv·2014-11-10·CVSS 4.3
CVE-2014-8369 [MEDIUM] CVE-2014-8369: The kvm_iommu_map_pages function in virt/kvm/iommu
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.
Kernel
kvm: fix excessive pages un-pinning in kvm_iommu_map error path.
kernel_security·2014-10-17·CVSS 4.3
CVE-2014-3601 [MEDIUM] kvm: fix excessive pages un-pinning in kvm_iommu_map error path.
kvm: fix excessive pages un-pinning in kvm_iommu_map error path.
The third parameter of kvm_unpin_pages() when called from
kvm_iommu_map_pages() is wrong, it should be the number of pages to un-pin
and not the page size.
This error was facilitated with an inconsistent API: kvm_pin_pages() takes
a size, but kvn_unpin_pages() takes a number of pages, so fix the problem
by matching the two.
This was introduced by commit 350b8bd ("kvm: iommu: fix the third parameter
of kvm_iommu_put_pages (CVE-2014-3601)"), which fixes the lack of
un-pinning for pages intended to be un-pinned (i.e. memory leak) but
unfortunately potentially aggravated the number of pages we un-pin that
should have stayed pinned. As far as I understand though, the same
practical mitigations apply.
This issue was found durin
OSV
linux vulnerabilities
osv·2014-09-23·CVSS 4.3
CVE-2014-3601 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jack Morgenstein reported a flaw in the page handling of the KVM (Kerenl
Virtual Machine) subsystem in the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service (host OS memory corruption)
or possibly have other unspecified impact on the host OS. (CVE-2014-3601)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Chris Evans reported an flaw in the Linux kernel's handling of iso9660
(compact disk filesystem) images. An attacker who can mount a custom
iso9660 image either via a CD/DVD drive or a loopback mount could cause a
denial of service (system crash or reboot). (CVE-2014-5471)
Chris
OSV
CVE-2014-3601: The kvm_iommu_map_pages function in virt/kvm/iommu
osv·2014-09-01·CVSS 4.3
CVE-2014-3601 [MEDIUM] CVE-2014-3601: The kvm_iommu_map_pages function in virt/kvm/iommu
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
kernel_security·2014-08-20·CVSS 4.3
CVE-2014-3601 [MEDIUM] Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Pull KVM fixes from Paolo Bonzini:
"Reverting a 3.16 patch, fixing two bugs in device assignment (one has
a CVE), and fixing some problems introduced during the merge window
(the CMA bug came in via Andrew, the x86 ones via yours truly)"
* tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm:
virt/kvm/assigned-dev.c: Set 'dev->irq_source_id' to '-1' after free it
Revert "KVM: x86: Increase the number of fixed MTRR regs to 10"
KVM: x86: do not check CS.DPL against RPL during task switch
KVM: x86: Avoid emulating instructions on #UD mistakenly
PC, KVM, CMA: Fix regression caused by wrong get_order() use
kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601)
Kernel
kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601)
kernel_security·2014-08-19·CVSS 4.3
CVE-2014-3601 [MEDIUM] kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601)
kvm: iommu: fix the third parameter of kvm_iommu_put_pages (CVE-2014-3601)
The third parameter of kvm_iommu_put_pages is wrong,
It should be 'gfn - slot->base_gfn'.
By making gfn very large, malicious guest or userspace can cause kvm to
go to this error path, and subsequently to pass a huge value as size.
Alternatively if gfn is small, then pages would be pinned but never
unpinned, causing host memory leak and local DOS.
Passing a reasonable but large value could be the most dangerous case,
because it would unpin a page that should have stayed pinned, and thus
allow the device to DMA into arbitrary memory. However, this cannot
happen because of the condition that can trigger the error:
- out of memory (where you can't allocate even a single page)
should not be possible for the attacker
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8369 kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path
bugzilla·2014-10-24·CVSS 4.3
CVE-2014-8369 [MEDIUM] CVE-2014-8369 kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path
CVE-2014-8369 kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path
A flaw was found in the way iommu mapping failures were handled in
kvm_iommu_map_pages() function in the Linux kernel (introduced by the fix
for CVE-2014-3601).
A privileged user in the guest could use this flaw to crash the host in case
the guest has access to passed in device.
Introduced by:
http://git.kernel.org/cgit/virt/kvm/kvm.git/commit/?id=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7
Upstream patch:
http://git.kernel.org/cgit/virt/kvm/kvm.git/commit/?id=3d32e4dbe71374a6780eaf51d719d76f9a9bf22f
Discussion:
Statement:
This issue did not affect the Linux kernel versions as shipped with Red Hat Enterprise Linux 5, 7 and Red Hat Enterprise MRG 2. Future Linux kernel updates for Red Hat Enterprise Linux
Bugzilla
CVE-2014-3601 kernel: kvm: invalid parameter passing in kvm_iommu_map_pages() [fedora-all]
bugzilla·2014-09-19·CVSS 4.3
CVE-2014-3601 [MEDIUM] CVE-2014-3601 kernel: kvm: invalid parameter passing in kvm_iommu_map_pages() [fedora-all]
CVE-2014-3601 kernel: kvm: invalid parameter passing in kvm_iommu_map_pages() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-3601 kernel: kvm: invalid parameter passing in kvm_iommu_map_pages()
bugzilla·2014-08-20·CVSS 4.3
CVE-2014-3601 [MEDIUM] CVE-2014-3601 kernel: kvm: invalid parameter passing in kvm_iommu_map_pages()
CVE-2014-3601 kernel: kvm: invalid parameter passing in kvm_iommu_map_pages()
A flaw was found in the way iommu mapping failures were handled in
kvm_iommu_map_pages() function in the Linux kernel. A privileged user in the
guest could use this flaw to crash the host in case the guest has access to
passed in device.
Acknowledgements:
Red Hat would like to thank Jack Morgenstein of Mellanox for reporting this issue; the security impact of this issue was discovered by Michael Tsirkin of Red Hat.
Discussion:
Upstream fix:
http://git.kernel.org/cgit/virt/kvm/kvm.git/commit/?id=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7
---
Statement:
This issue did not affect the Linux kernel versions as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2. Future kvm updates for Red Hat E
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://secunia.com/advisories/60830http://www.securityfocus.com/bid/69489http://www.ubuntu.com/usn/USN-2356-1http://www.ubuntu.com/usn/USN-2357-1http://www.ubuntu.com/usn/USN-2358-1http://www.ubuntu.com/usn/USN-2359-1https://bugzilla.redhat.com/show_bug.cgi?id=1131951https://exchange.xforce.ibmcloud.com/vulnerabilities/95689https://github.com/torvalds/linux/commit/350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://secunia.com/advisories/60830http://www.securityfocus.com/bid/69489http://www.ubuntu.com/usn/USN-2356-1http://www.ubuntu.com/usn/USN-2357-1http://www.ubuntu.com/usn/USN-2358-1http://www.ubuntu.com/usn/USN-2359-1https://bugzilla.redhat.com/show_bug.cgi?id=1131951https://exchange.xforce.ibmcloud.com/vulnerabilities/95689https://github.com/torvalds/linux/commit/350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7
2014-09-01
Published