CVE-2014-3610Uncaught Exception in Kernel

CWE-248Uncaught Exception17 documents9 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 84.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 13

Description

The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel< 3.17.2
Debianlinux/linux_kernel< 3.16.7-1+3
Ubuntulinux/linux_kernel< 3.13.0-39.66

Also affects: Ubuntu Linux 10.04, 12.04, Debian Linux 7.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-f8g7-wvf8-qh5r: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 32022-05-13
CVEList
CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 32014-11-10
OSV
CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 32014-11-10
OSV
CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 32014-10-23
Kernel
KVM: x86: Check non-canonical addresses upon WRMSR2014-09-16

📋Vendor Advisories

9
Ubuntu
Linux kernel (EC2) vulnerabilities2015-02-04
Ubuntu
Linux kernel vulnerabilities2015-01-13
Ubuntu
Linux kernel vulnerabilities2014-11-25
Ubuntu
Linux kernel (OMAP4) vulnerabilities2014-11-25
Ubuntu
Linux kernel vulnerabilities2014-10-31

💬Community

2
Bugzilla
CVE-2014-3610 kernel: kvm: noncanonical MSR writes [fedora-all]2014-10-24
Bugzilla
CVE-2014-3610 kernel: kvm: noncanonical MSR writes2014-09-21
CVE-2014-3610 — Uncaught Exception in Linux Kernel | cvebase