CVE-2014-7842
published 2014-11-30CVE-2014-7842: Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted…
PriorityP417medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.37%
30.3th percentile
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
Affected
186 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.38-1 (bookworm) | linux 2.6.38-1 (bookworm) |
| debian | linux | < linux 3.16.7-ckt2-1 (bookworm) | linux 3.16.7-ckt2-1 (bookworm) |
| linux | linux_kernel | <= 2.6.37 | — |
| linux | linux_kernel | <= 3.17.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 4.9
CVE-2014-7842 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovere
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 4.9
CVE-2014-7842 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
The KVM (kernel virtual machine) subsystem of the Linux kernel
miscalculates the number of memory pages during the handling of a mapping
failure. A guest OS user could exploit this to cause a denial of service
(host OS page unpinning) or possibly have unspecified other impact by
leveraging guest OS privileges. (CVE-2014-8369)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (syst
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (system crash) by
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (syst
Red Hat
kernel: kvm: reporting emulation failures to userspace
vendor_redhat·2014-09-24·CVSS 4.9
CVE-2014-7842 [MEDIUM] kernel: kvm: reporting emulation failures to userspace
kernel: kvm: reporting emulation failures to userspace
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
It was found that reporting emulation failures to user space could lead to either a local (CVE-2014-7842) or a L2->L1 (CVE-2010-5313) denial of service. In the case of a local denial of service, an attacker must have access to the MMIO area or be able to access an I/O port. Please note that on certain systems, HPET is mapped to userspace as part of vdso (vvar) and thus an unprivileged user may generate MMIO transactions (and enter t
Red Hat
kernel: kvm: reporting emulation failures to userspace
vendor_redhat·2014-09-24·CVSS 4.9
CVE-2010-5313 [MEDIUM] kernel: kvm: reporting emulation failures to userspace
kernel: kvm: reporting emulation failures to userspace
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
It was found that reporting emulation failures to user space could lead to either a local (CVE-2014-7842) or a L2->L1 (CVE-2010-5313) denial of service. In the case of a local denial of service, an attacker must have access to the MMIO area or be able to access an I/O port. Please note that on certain systems, HPET is mapped to userspace as part of vdso (vvar) and thus an unprivileged user may generate MMIO transactions (and enter the emulator) this way.
Statement: This issue did not af
Debian
CVE-2014-7842: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows gu...
vendor_debian·2014·CVSS 4.9
CVE-2014-7842 [MEDIUM] CVE-2014-7842: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows gu...
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1)
sid: resolved (fixed in 3.16.7-ckt2-1)
trixie: resolved (fixed in 3.16.7-ckt2-1)
Debian
CVE-2010-5313: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2...
vendor_debian·2010·CVSS 4.9
CVE-2010-5313 [MEDIUM] CVE-2010-5313: linux - Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2...
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
Scope: local
bookworm: resolved (fixed in 2.6.38-1)
bullseye: resolved (fixed in 2.6.38-1)
forky: resolved (fixed in 2.6.38-1)
sid: resolved (fixed in 2.6.38-1)
trixie: resolved (fixed in 2.6.38-1)
GHSA
GHSA-8hgg-pmrm-w85w: Race condition in arch/x86/kvm/x86
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-5313 [MEDIUM] CWE-362 GHSA-8hgg-pmrm-w85w: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
GHSA
GHSA-5j6g-rhrc-x47f: Race condition in arch/x86/kvm/x86
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2014-7842 [MEDIUM] CWE-362 GHSA-5j6g-rhrc-x47f: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
OSV
linux vulnerabilities
osv·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (system crash) by reading one byte beyond a
/dev/zero page boundary. (CVE-2014-7843)
A stac
OSV
linux-lts-utopic vulnerabilities
osv·2015-01-13·CVSS 5.0
CVE-2014-7841 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a denial of service (system crash) via a malformed INIT
chunk. (CVE-2014-7841)
A race condition with MMIO and PIO transactions in the KVM (Kernel Virtual
Machine) subsystem of the Linux kernel was discovered. A guest OS user
could exploit this flaw to cause a denial of service (guest OS crash) via a
specially crafted application. (CVE-2014-7842)
Miloš Prchlík reported a flaw in how the ARM64 platform handles a single
byte overflow in __clear_user. A local user could exploit this flaw to
cause a denial of service (system crash) by reading one byte beyond a
/dev/zero page boundary. (CVE-2014-78
OSV
CVE-2014-7842: Race condition in arch/x86/kvm/x86
osv·2014-11-30·CVSS 4.9
CVE-2014-7842 [MEDIUM] CVE-2014-7842: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation error report, a similar issue to CVE-2010-5313.
OSV
CVE-2010-5313: Race condition in arch/x86/kvm/x86
osv·2014-11-30·CVSS 4.9
CVE-2010-5313 [MEDIUM] CVE-2010-5313: Race condition in arch/x86/kvm/x86
Race condition in arch/x86/kvm/x86.c in the Linux kernel before 2.6.38 allows L2 guest OS users to cause a denial of service (L1 guest OS crash) via a crafted instruction that triggers an L2 emulation failure report, a similar issue to CVE-2014-7842.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7842 kernel: kvm: reporting emulation failures to userspace [fedora-all]
bugzilla·2014-11-13·CVSS 4.9
CVE-2014-7842 [MEDIUM] CVE-2014-7842 kernel: kvm: reporting emulation failures to userspace [fedora-all]
CVE-2014-7842 kernel: kvm: reporting emulation failures to userspace [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2010-5313 CVE-2014-7842 kernel: kvm: reporting emulation failures to userspace
bugzilla·2014-11-13·CVSS 4.9
CVE-2010-5313 [MEDIUM] CVE-2010-5313 CVE-2014-7842 kernel: kvm: reporting emulation failures to userspace
CVE-2010-5313 CVE-2014-7842 kernel: kvm: reporting emulation failures to userspace
It was found that reporting emulation failures to user space can lead to either
local (CVE-2014-7842) or L2->L1 (CVE-2010-5313) DoS.
In the case of local DoS attacker needs access to MMIO area or be able to
generate port access. Please note that on certain systems HPET is mapped
to userspace as part of vdso (vvar) and thus an unprivileged user may
generate MMIO transactions (and enter the emulator) this way.
Upstream patches:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=fc3a9157d314
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a2b9e6c1a35a
Acknowledgements:
Red Hat would like to thank Nadav Amit for reporting this issue.
Discussion:
Created
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a2b9e6c1a35afcc0973acb72e591c714e78885ffhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://secunia.com/advisories/62305http://secunia.com/advisories/62326http://secunia.com/advisories/62336http://www.openwall.com/lists/oss-security/2014/11/13/7http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71078https://bugzilla.redhat.com/show_bug.cgi?id=1163762https://github.com/torvalds/linux/commit/a2b9e6c1a35afcc0973acb72e591c714e78885ffhttps://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.4http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a2b9e6c1a35afcc0973acb72e591c714e78885ffhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0855.htmlhttp://secunia.com/advisories/62305http://secunia.com/advisories/62326http://secunia.com/advisories/62336http://www.openwall.com/lists/oss-security/2014/11/13/7http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71078https://bugzilla.redhat.com/show_bug.cgi?id=1163762https://github.com/torvalds/linux/commit/a2b9e6c1a35afcc0973acb72e591c714e78885ffhttps://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.4
2014-11-30
Published