CVE-2014-3646
published 2014-11-10CVE-2014-3646: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.43%
34.7th percentile
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-1 (bookworm) | linux 3.16.7-1 (bookworm) |
| linux | linux_kernel | <= 3.17.2 | — |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-39.66 | 3.13.0-39.66 |
| openstack | keystone | >= 2011.3 < 2014.1.5 | 2014.1.5 |
| openstack | keystone | >= 2014.2 < 2014.2.4 | 2014.2.4 |
| opensuse | evergreen | — | — |
| redhat | enterprise_linux | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xq4c-q7v4-538j: arch/x86/kvm/vmx
ghsa_unreviewed·2022-05-13
CVE-2014-3646 [MEDIUM] GHSA-xq4c-q7v4-538j: arch/x86/kvm/vmx
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
GHSA
OpenStack Keystone Logs Passwords
ghsa·2022-05-13
CVE-2015-3646 [MEDIUM] CWE-200 OpenStack Keystone Logs Passwords
OpenStack Keystone Logs Passwords
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
OSV
CVE-2014-3646: arch/x86/kvm/vmx
osv·2014-11-10·CVSS 5.5
CVE-2014-3646 [MEDIUM] CVE-2014-3646: arch/x86/kvm/vmx
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
OSV
linux vulnerabilities
osv·2014-10-30·CVSS 6.9
CVE-2014-3647 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Linux
kernel. A local guest user with access to PIT i/o ports could exploit t
OSV
CVE-2014-3646: arch/x86/kvm/vmx
osv·2014-10-23·CVSS 5.5
CVE-2014-3646 [MEDIUM] CVE-2014-3646: arch/x86/kvm/vmx
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. A local unprivileged guest user could use this flaw to crash the guest.
Kernel
kvm: vmx: handle invvpid vm exit gracefully
kernel_security·2014-09-23·CVSS 5.5
CVE-2014-3646 [MEDIUM] kvm: vmx: handle invvpid vm exit gracefully
kvm: vmx: handle invvpid vm exit gracefully
On systems with invvpid instruction support (corresponding bit in
IA32_VMX_EPT_VPID_CAP MSR is set) guest invocation of invvpid
causes vm exit, which is currently not handled and results in
propagation of unknown exit to userspace.
Fix this by installing an invvpid vm exit handler.
This is CVE-2014-3646.
Cc: [email protected]
Signed-off-by: Petr Matousek
Signed-off-by: Paolo Bonzini
Red Hat
openstack-keystone: cache backend password leak in log (OSSA 2015-008)
vendor_redhat·2015-05-04·CVSS 4.0
CVE-2015-3646 [MEDIUM] CWE-732 openstack-keystone: cache backend password leak in log (OSSA 2015-008)
openstack-keystone: cache backend password leak in log (OSSA 2015-008)
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Statement: While this issue does occur in openstack-keystone packages as shipped in Red Hat Enterprise Linux OpenStack Platform versions 5 and 6 it is not believed to be exploitable as access to the keystone logs is restricted with file-system permissions.
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Packag
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
A flaw was discovered with invept instruction support when using nested EPT
in the KVM (Kernel Virtual Machine). An unprivileged guest user coul
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
A flaw was discovered with invept instruction support when using nested EPT
in the KVM (Kernel Virtual Machine). An unprivileged guest u
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-31·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Lin
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 6.9
CVE-2014-3182 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Lin
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 6.9
CVE-2014-3182 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsyst
Red Hat
kernel: kvm: vmx: invvpid vm exit not handled
vendor_redhat·2014-10-21·CVSS 5.5
CVE-2014-3646 [MEDIUM] CWE-248 kernel: kvm: vmx: invvpid vm exit not handled
kernel: kvm: vmx: invvpid vm exit not handled
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
It was found that the Linux kernel's KVM subsystem did not handle the VM exits gracefully for the invvpid (Invalidate Translations Based on VPID) instructions. On hosts with an Intel processor and invppid VM exit support, an unprivileged guest user could use these instructions to crash the guest.
Statement: This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6 and 7. Future updates may address this issue in the
respective Red Hat Enterprise Linux releases.
This issue does a
Debian
CVE-2014-3646: linux - arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does ...
vendor_debian·2014·CVSS 5.5
CVE-2014-3646 [MEDIUM] CVE-2014-3646: linux - arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does ...
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.16.7-1)
bullseye: resolved (fixed in 3.16.7-1)
forky: resolved (fixed in 3.16.7-1)
sid: resolved (fixed in 3.16.7-1)
trixie: resolved (fixed in 3.16.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3646 kernel: kvm: vmx: invvpid vm exit not handled [fedora-all]
bugzilla·2014-10-24·CVSS 5.5
CVE-2014-3646 [MEDIUM] CVE-2014-3646 kernel: kvm: vmx: invvpid vm exit not handled [fedora-all]
CVE-2014-3646 kernel: kvm: vmx: invvpid vm exit not handled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2014-3646 kernel: kvm: vmx: invvpid vm exit not handled
bugzilla·2014-09-21·CVSS 5.5
CVE-2014-3646 [MEDIUM] CVE-2014-3646 kernel: kvm: vmx: invvpid vm exit not handled
CVE-2014-3646 kernel: kvm: vmx: invvpid vm exit not handled
On systems with invvpid instruction support (corresponding bit in
IA32_VMX_EPT_VPID_CAP MSR is set) guest invocation of invvpid
causes vm exit, which is currently not handled and causes unknown
exit error to be propagated to userspace.
A local unprivileged guest user could use this flaw to crash the
guest.
Acknowledgements:
Red Hat would like to thank the Advanced Threat Research team at Intel Security for reporting this issue.
Discussion:
Statement:
This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 6 and 7. Future updates may address this issue in the
respective Red Hat Enterprise Linux releases.
This issue does affect the kvm packages as shipped with Red Hat Enterprise Linux 5.
Re
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a642fc305053cc1c6e47e4f4df327895747ab485http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0126.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.debian.org/security/2014/dsa-3060http://www.openwall.com/lists/oss-security/2014/10/24/9http://www.ubuntu.com/usn/USN-2394-1http://www.ubuntu.com/usn/USN-2417-1http://www.ubuntu.com/usn/USN-2418-1https://bugzilla.redhat.com/show_bug.cgi?id=1144825https://github.com/torvalds/linux/commit/a642fc305053cc1c6e47e4f4df327895747ab485http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a642fc305053cc1c6e47e4f4df327895747ab485http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0126.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.debian.org/security/2014/dsa-3060http://www.openwall.com/lists/oss-security/2014/10/24/9http://www.ubuntu.com/usn/USN-2394-1http://www.ubuntu.com/usn/USN-2417-1http://www.ubuntu.com/usn/USN-2418-1https://bugzilla.redhat.com/show_bug.cgi?id=1144825https://github.com/torvalds/linux/commit/a642fc305053cc1c6e47e4f4df327895747ab485
2014-11-10
Published