CVE-2014-8369

CWE-119Buffer Overflow14 documents8 sources
Severity
7.8HIGH
EPSS
0.1%
top 76.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 13

Description

The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Also affects: Debian Linux 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-78qf-3xpg-qfgr: The kvm_iommu_map_pages function in virt/kvm/iommu2022-05-13
OSV
CVE-2014-8369: The kvm_iommu_map_pages function in virt/kvm/iommu2014-11-10
CVEList
CVE-2014-8369: The kvm_iommu_map_pages function in virt/kvm/iommu2014-11-10

📋Vendor Advisories

8
Ubuntu
Linux kernel (OMAP4) vulnerabilities2015-01-13
Ubuntu
Linux kernel vulnerabilities2015-01-13
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities2014-12-12
Ubuntu
Linux kernel vulnerabilities2014-12-12
Ubuntu
Linux kernel vulnerabilities2014-12-12

💬Community

2
Bugzilla
CVE-2014-8369 kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path2014-10-24
Bugzilla
CVE-2014-8369 kernel: kvm: excessive pages un-pinning in kvm_iommu_map error path [fedora-all]2014-10-24