CVE-2014-8159
published 2015-03-16CVE-2014-8159: The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of…
PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.44%
36.3th percentile
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt9-1 (bookworm) | linux 3.16.7-ckt9-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 2.6.12 < 3.2.69 | 3.2.69 |
| linux | linux_kernel | >= 3.11 < 3.12.41 | 3.12.41 |
| linux | linux_kernel | >= 3.13 < 3.14.39 | 3.14.39 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.13 | 3.18.13 |
| linux | linux_kernel | >= 3.19 < 3.19.5 | 3.19.5 |
| linux | linux_kernel | >= 3.3 < 3.4.108 | 3.4.108 |
| linux | linux_kernel | >= 3.5 < 3.10.75 | 3.10.75 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-04-08·CVSS 6.9
CVE-2014-8159 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.
(CVE-2014-8159)
An integer overflow was discovered in the stack randomization feature of
the Linux kernel on 64 bit platforms. A local attacker could exploit this
flaw to bypass the Address Space Layout Randomization (ASLR) protection
mechanism. (CVE-2015-1593)
An information leak was discovered in the Linux Kernel's handling of
userspace configuration of the link layer control (LLC). A local user co
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-03-12
CVE-2014-8159 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2015-03-12
CVE-2014-8159 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-03-12
CVE-2014-8159 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
kernel: infiniband: uverbs: unprotected physical memory access
vendor_redhat·2015-03-11·CVSS 6.9
CVE-2014-8159 [MEDIUM] CWE-190 kernel: infiniband: uverbs: unprotected physical memory access
kernel: infiniband: uverbs: unprotected physical memory access
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
It was found that the Linux kernel's Infiniband subsystem did not properly sanitize input parameters while registering memory regions from user space via the (u)verbs API. A local user with access to a /dev/infiniband/uverbsX device could use this flaw to crash the system or, potentially, escalate their privile
Debian
CVE-2014-8159: linux - The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504...
vendor_debian·2014·CVSS 6.9
CVE-2014-8159 [MEDIUM] CVE-2014-8159: linux - The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504...
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt9-1)
bullseye: resolved (fixed in 3.16.7-ckt9-1)
forky: resolved (fixed in 3.16.7-ckt9-1)
sid: resolved (fixed in 3.16.7-ckt9-1)
trixie: resolved (fixed in 3.16.7-ckt9-1)
GHSA
GHSA-355g-wjmx-fcfq: The InfiniBand (IB) implementation in the Linux kernel package before 2
ghsa_unreviewed·2022-05-14
CVE-2014-8159 [MEDIUM] GHSA-355g-wjmx-fcfq: The InfiniBand (IB) implementation in the Linux kernel package before 2
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
Kernel
IB/uverbs: Prevent integer overflow in ib_umem_get address arithmetic
kernel_security·2015-03-18·CVSS 6.9
CVE-2014-8159 [MEDIUM] IB/uverbs: Prevent integer overflow in ib_umem_get address arithmetic
IB/uverbs: Prevent integer overflow in ib_umem_get address arithmetic
Properly verify that the resulting page aligned end address is larger
than both the start address and the length of the memory area requested.
Both the start and length arguments for ib_umem_get are controlled by
the user. A misbehaving user can provide values which will cause an
integer overflow when calculating the page aligned end address.
This overflow can cause also miscalculation of the number of pages
mapped, and additional logic issues.
Addresses: CVE-2014-8159
Cc:
Signed-off-by: Shachar Raindel
Signed-off-by: Jack Morgenstein
Signed-off-by: Or Gerlitz
Signed-off-by: Roland Dreier
OSV
CVE-2014-8159: The InfiniBand (IB) implementation in the Linux kernel package before 2
osv·2015-03-16·CVSS 6.9
CVE-2014-8159 [MEDIUM] CVE-2014-8159: The InfiniBand (IB) implementation in the Linux kernel package before 2
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access [fedora-all]
bugzilla·2015-03-11·CVSS 6.9
CVE-2014-8159 [MEDIUM] CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access [fedora-all]
CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access
bugzilla·2015-01-12·CVSS 6.9
CVE-2014-8159 [MEDIUM] CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access
CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access
It was found that the Linux kernel's Infiniband subsystem did not properly
sanitize input parameters while registering memory regions from the userspace
via the (u)verbs API. As a result, an unrestricted physical memory access
could be achieved.
A local user with access to /dev/infiniband/uverbsX could use this flaw to
crash the system or, potentially, escalate their privileges on the system.
Discussion:
Statement:
This issue did affect the Linux kernel packages as shipped with Red Hat
Enterprise Linux 5, 6, and 7, and Red Hat Enterprise MRG 2. This issue
has been addressed in the respective releases.
---
Acknowledgements:
Red Hat would like to thank Mellanox for reporting this issue.
---
This issue has
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152747.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0674.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0695.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0751.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0783.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0803.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0870.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0919.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.securityfocus.com/bid/73060http://www.securitytracker.com/id/1032224http://www.ubuntu.com/usn/USN-2525-1http://www.ubuntu.com/usn/USN-2526-1http://www.ubuntu.com/usn/USN-2527-1http://www.ubuntu.com/usn/USN-2528-1http://www.ubuntu.com/usn/USN-2529-1http://www.ubuntu.com/usn/USN-2530-1http://www.ubuntu.com/usn/USN-2561-1https://bugzilla.redhat.com/show_bug.cgi?id=1181166http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152747.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0674.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0695.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0726.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0751.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0783.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0803.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0870.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0919.htmlhttp://www.debian.org/security/2015/dsa-3237http://www.securityfocus.com/bid/73060http://www.securitytracker.com/id/1032224http://www.ubuntu.com/usn/USN-2525-1http://www.ubuntu.com/usn/USN-2526-1http://www.ubuntu.com/usn/USN-2527-1http://www.ubuntu.com/usn/USN-2528-1http://www.ubuntu.com/usn/USN-2529-1http://www.ubuntu.com/usn/USN-2530-1http://www.ubuntu.com/usn/USN-2561-1https://bugzilla.redhat.com/show_bug.cgi?id=1181166
2015-03-16
Published