CVE-2014-3645
published 2014-11-10CVE-2014-3645: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.41%
34.0th percentile
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Affected
243 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.12.6-1 (bookworm) | linux 3.12.6-1 (bookworm) |
| linux | linux_kernel | <= 3.11.7 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_ubuntu5.5MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
A flaw was discovered with invept instruction support when using nested EPT
in the KVM (Kernel Virtual Machine). An unprivileged guest user coul
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
A flaw was discovered with invept instruction support when using nested EPT
in the KVM (Kernel Virtual Machine). An unprivileged guest u
Red Hat
kernel: kvm: vmx: invept vm exit not handled
vendor_redhat·2014-10-21·CVSS 2.1
CVE-2014-3645 [LOW] CWE-248 kernel: kvm: vmx: invept vm exit not handled
kernel: kvm: vmx: invept vm exit not handled
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
It was found that the Linux kernel's KVM subsystem did not handle the VM exits gracefully for the invept (Invalidate Translations Derived from EPT) instructions. On hosts with an Intel processor and invept VM exit support, an unprivileged guest user could use these instructions to crash the guest.
Statement: This issue does affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 6 and 7. Future updates may address this issue in the
respective Red Hat Enterprise Linux releases.
This issue does affe
Debian
CVE-2014-3645: linux - arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not...
vendor_debian·2014·CVSS 2.1
CVE-2014-3645 [LOW] CVE-2014-3645: linux - arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not...
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.12.6-1)
bullseye: resolved (fixed in 3.12.6-1)
forky: resolved (fixed in 3.12.6-1)
sid: resolved (fixed in 3.12.6-1)
trixie: resolved (fixed in 3.12.6-1)
GHSA
GHSA-26g3-v5f7-pgv9: arch/x86/kvm/vmx
ghsa_unreviewed·2022-05-17
CVE-2014-3645 [LOW] CWE-20 GHSA-26g3-v5f7-pgv9: arch/x86/kvm/vmx
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
OSV
CVE-2014-3645: arch/x86/kvm/vmx
osv·2014-11-10·CVSS 2.1
CVE-2014-3645 [LOW] CVE-2014-3645: arch/x86/kvm/vmx
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. A local unprivileged guest user could use this flaw to crash the guest.
OSV
CVE-2014-3645: arch/x86/kvm/vmx
osv·2014-11-10·CVSS 2.1
CVE-2014-3645 [LOW] CVE-2014-3645: arch/x86/kvm/vmx
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bfd0a56b90005f8c8a004baf407ad90045c2b11ehttp://rhn.redhat.com/errata/RHSA-2015-0126.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.debian.org/security/2014/dsa-3060http://www.openwall.com/lists/oss-security/2014/10/24/9http://www.ubuntu.com/usn/USN-2417-1http://www.ubuntu.com/usn/USN-2418-1https://bugzilla.redhat.com/show_bug.cgi?id=1144835https://github.com/torvalds/linux/commit/bfd0a56b90005f8c8a004baf407ad90045c2b11ehttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bfd0a56b90005f8c8a004baf407ad90045c2b11ehttp://rhn.redhat.com/errata/RHSA-2015-0126.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.debian.org/security/2014/dsa-3060http://www.openwall.com/lists/oss-security/2014/10/24/9http://www.ubuntu.com/usn/USN-2417-1http://www.ubuntu.com/usn/USN-2418-1https://bugzilla.redhat.com/show_bug.cgi?id=1144835https://github.com/torvalds/linux/commit/bfd0a56b90005f8c8a004baf407ad90045c2b11e
2014-11-10
Published