CVE-2015-0239
published 2015-03-02CVE-2015-0239: The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS…
PriorityP420medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.64%
47.1th percentile
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt4-2 (bookworm) | linux 3.16.7-ckt4-2 (bookworm) |
| linux | linux_kernel | < 3.18.5 | 3.18.5 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.13.0-46.77 | 3.13.0-46.77 |
| linux | linux_kernel | >= 0 < 3.13.0-46.75 | 3.13.0-46.75 |
| linux | linux_kernel | >= 0 < 3.13.0-46.76 | 3.13.0-46.76 |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities regression
vendor_ubuntu·2015-03-04·CVSS 2.1
[LOW] Linux kernel (Trusty HWE) vulnerabilities regression
Title: Linux kernel (Trusty HWE) vulnerabilities regression
Summary: USN-2515-1 introduced a regression in the Linux kernel.
USN-2515-1 fixed vulnerabilities in the Linux kernel. There was an unrelated
regression in the use of the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementat
Ubuntu
Linux kernel vulnerabilities regression
vendor_ubuntu·2015-03-04·CVSS 2.1
[LOW] Linux kernel vulnerabilities regression
Title: Linux kernel vulnerabilities regression
Summary: USN-2516-1 introduced a regression in the Linux kernel.
USN-2516-1 fixed vulnerabilities in the Linux kernel, and the fix in
USN-2516-2 was incomplete. There was an unrelated regression in the use of
the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
L
Ubuntu
Linux kernel vulnerability regression
vendor_ubuntu·2015-02-28·CVSS 2.1
[LOW] Linux kernel vulnerability regression
Title: Linux kernel vulnerability regression
Summary: USN-2516-1 introduced a regression in the Linux kernel.
USN-2516-1 fixed vulnerabilities in the Linux kernel. There was an unrelated
regression in the use of the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing us
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2014-8133 [LOW] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chro
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2014-8133 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A res
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2014-8133 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A res
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2014-8133 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chroot direc
Red Hat
kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code
vendor_redhat·2015-01-27·CVSS 4.4
CVE-2015-0239 [MEDIUM] CWE-391 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code
kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
It was found that the Linux kernel KVM subsystem's sysenter instruction emulation was not sufficient. An unprivileged guest user could use this flaw to escalate their privileges by tricking the hypervisor to emulate a SYSENTER instruction in 16-bit mode, if the guest OS did not initialize the SYSENTER model-specific registers (MSRs). Note: Certified guest operating systems for Red Hat Enterprise Linux
Debian
CVE-2015-0239: linux - The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3....
vendor_debian·2015·CVSS 4.4
CVE-2015-0239 [MEDIUM] CVE-2015-0239: linux - The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3....
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-2)
bullseye: resolved (fixed in 3.16.7-ckt4-2)
forky: resolved (fixed in 3.16.7-ckt4-2)
sid: resolved (fixed in 3.16.7-ckt4-2)
trixie: resolved (fixed in 3.16.7-ckt4-2)
GHSA
GHSA-h9w7-gg89-fg55: The em_sysenter function in arch/x86/kvm/emulate
ghsa_unreviewed·2022-05-13
CVE-2015-0239 [MEDIUM] CWE-269 GHSA-h9w7-gg89-fg55: The em_sysenter function in arch/x86/kvm/emulate
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
OSV
linux vulnerabilities
osv·2015-03-04·CVSS 2.1
[LOW] linux vulnerabilities
linux vulnerabilities
USN-2516-1 fixed vulnerabilities in the Linux kernel, and the fix in
USN-2516-2 was incomplete. There was an unrelated regression in the use of
the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information
OSV
CVE-2015-0239: The em_sysenter function in arch/x86/kvm/emulate
osv·2015-03-02·CVSS 4.4
CVE-2015-0239 [MEDIUM] CVE-2015-0239: The em_sysenter function in arch/x86/kvm/emulate
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
OSV
linux vulnerability
osv·2015-02-28·CVSS 2.1
[LOW] linux vulnerability
linux vulnerability
USN-2516-1 fixed vulnerabilities in the Linux kernel. There was an unrelated
regression in the use of the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Spa
OSV
linux vulnerabilities
osv·2015-02-26·CVSS 2.1
CVE-2015-0239 [LOW] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A restriction bypass was discovered in iptables when conntrack rules are
specif
OSV
linux-lts-utopic vulnerabilities
osv·2015-02-26·CVSS 2.1
CVE-2015-0239 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A restriction bypass was discovered in iptables when conntrack rules
Kernel
KVM: x86: SYSENTER emulation is broken
kernel_security·2015-01-01·CVSS 4.4
CVE-2015-0239 [MEDIUM] KVM: x86: SYSENTER emulation is broken
KVM: x86: SYSENTER emulation is broken
SYSENTER emulation is broken in several ways:
1. It misses the case of 16-bit code segments completely (CVE-2015-0239).
2. MSR_IA32_SYSENTER_CS is checked in 64-bit mode incorrectly (bits 0 and 1 can
still be set without causing #GP).
3. MSR_IA32_SYSENTER_EIP and MSR_IA32_SYSENTER_ESP are not masked in
legacy-mode.
4. There is some unneeded code.
Fix it.
Cc: [email protected]
Signed-off-by: Nadav Amit
Signed-off-by: Paolo Bonzini
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0239 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code [fedora-all]
bugzilla·2015-01-27·CVSS 4.4
CVE-2015-0239 [MEDIUM] CVE-2015-0239 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code [fedora-all]
CVE-2015-0239 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2015-0239 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code
bugzilla·2015-01-27·CVSS 4.4
CVE-2015-0239 [MEDIUM] CVE-2015-0239 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code
CVE-2015-0239 kernel: kvm: insufficient sysenter emulation when invoked from 16-bit code
It was found that the Linux kernel KVM subsystem's sysenter instruction
emulation was not sufficient.
An unprivileged guest user could use this flaw to escalate their privileges by
tricking the hypervisor to emulate a SYSENTER instruction in 16-bit mode, if
the guest OS does not initialize the SYSENTER MSRs.
Please note that the Red Hat Enterprise Linux with KVM certified guest operating
systems do initialize the SYSENTER MSRs and are thus not vulnerable to
this issue when running on KVM hypervisor.
References:
http://www.openwall.com/lists/oss-security/2015/01/27/6
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f3747379accba8e95d70cec0eae0582c8c182050
A
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f3747379accba8e95d70cec0eae0582c8c182050http://permalink.gmane.org/gmane.linux.kernel.commits.head/502245http://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.5http://www.mandriva.com/security/advisories?name=MDVSA-2015:058http://www.openwall.com/lists/oss-security/2015/01/27/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72842http://www.ubuntu.com/usn/USN-2513-1http://www.ubuntu.com/usn/USN-2514-1http://www.ubuntu.com/usn/USN-2515-1http://www.ubuntu.com/usn/USN-2516-1http://www.ubuntu.com/usn/USN-2517-1http://www.ubuntu.com/usn/USN-2518-1https://bugzilla.redhat.com/show_bug.cgi?id=1186448https://github.com/torvalds/linux/commit/f3747379accba8e95d70cec0eae0582c8c182050http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f3747379accba8e95d70cec0eae0582c8c182050http://permalink.gmane.org/gmane.linux.kernel.commits.head/502245http://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.5http://www.mandriva.com/security/advisories?name=MDVSA-2015:058http://www.openwall.com/lists/oss-security/2015/01/27/6http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72842http://www.ubuntu.com/usn/USN-2513-1http://www.ubuntu.com/usn/USN-2514-1http://www.ubuntu.com/usn/USN-2515-1http://www.ubuntu.com/usn/USN-2516-1http://www.ubuntu.com/usn/USN-2517-1http://www.ubuntu.com/usn/USN-2518-1https://bugzilla.redhat.com/show_bug.cgi?id=1186448https://github.com/torvalds/linux/commit/f3747379accba8e95d70cec0eae0582c8c182050
2015-03-02
Published