CVE-2015-5307
published 2015-11-16CVE-2015-5307: The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by…
PriorityP417medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.57%
43.2th percentile
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.2.6-1 (bookworm) | linux 4.2.6-1 (bookworm) |
| debian | virtualbox | < linux 4.2.6-1 (bookworm) | linux 4.2.6-1 (bookworm) |
| debian | xen | < linux 4.2.6-1 (bookworm) | linux 4.2.6-1 (bookworm) |
| linux | linux_kernel | <= 4.2.3 | — |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| linux | linux_kernel | >= 0 < 4.2.6-1 | 4.2.6-1 |
| oracle | vm_virtualbox | 4.0.0 – 4.0.34 | — |
| oracle | vm_virtualbox | 4.1.0 – 4.1.42 | — |
| oracle | vm_virtualbox | 4.2.0 – 4.2.34 | — |
| oracle | vm_virtualbox | 4.3.0 – 4.3.29 | — |
| oracle | vm_virtualbox | 5.0.0 – 5.0.8 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2015-11-10
CVE-2015-5307 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Ben Serebrin discovered that the KVM hypervisor implementation in the Linux
kernel did not properly catch Alignment Check exceptions. An attacker in a
guest virtual machine could use this to cause a denial of service (system
crash) in the host OS.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel versi
Red Hat
virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
vendor_redhat·2015-11-10·CVSS 4.9
CVE-2015-5307 [MEDIUM] CWE-835 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
It was found that the x86 ISA (Instruction Set Architecture) is prone to a denial of service attack inside a virtualized environment in the form of an infinite loop in the microcode due to the way (sequential) delivering of benign exceptions such as #AC (alignment check exception) is handled. A privileged user inside a guest could use this flaw to create denial of service conditions on the host kernel.
Statement: This issue affects the version of the kvm and xen pa
Ubuntu
Linux kernel (Utopic HWE) vulnerability
vendor_ubuntu·2015-11-10
CVE-2015-5307 Linux kernel (Utopic HWE) vulnerability
Title: Linux kernel (Utopic HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Ben Serebrin discovered that the KVM hypervisor implementation in the Linux
kernel did not properly catch Alignment Check exceptions. An attacker in a
guest virtual machine could use this to cause a denial of service (system
crash) in the host OS.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new
Ubuntu
Linux kernel (Vivid HWE) vulnerability
vendor_ubuntu·2015-11-10
CVE-2015-5307 Linux kernel (Vivid HWE) vulnerability
Title: Linux kernel (Vivid HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Ben Serebrin discovered that the KVM hypervisor implementation in the Linux
kernel did not properly catch Alignment Check exceptions. An attacker in a
guest virtual machine could use this to cause a denial of service (system
crash) in the host OS.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2015-11-10
CVE-2015-5307 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Ben Serebrin discovered that the KVM hypervisor implementation in the Linux
kernel did not properly catch Alignment Check exceptions. An attacker in a
guest virtual machine could use this to cause a denial of service (system
crash) in the host OS.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new
Ubuntu
Linux kernel (Wily HWE) vulnerability
vendor_ubuntu·2015-11-10
CVE-2015-5307 Linux kernel (Wily HWE) vulnerability
Title: Linux kernel (Wily HWE) vulnerability
Summary: The system could be made to crash under certain conditions.
Ben Serebrin discovered that the KVM hypervisor implementation in the Linux
kernel did not properly catch Alignment Check exceptions. An attacker in a
guest virtual machine could use this to cause a denial of service (system
crash) in the host OS.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new k
Debian
CVE-2015-5307: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x...
vendor_debian·2015·CVSS 4.9
CVE-2015-5307 [MEDIUM] CVE-2015-5307: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x...
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
Scope: local
bookworm: resolved (fixed in 4.2.6-1)
bullseye: resolved (fixed in 4.2.6-1)
forky: resolved (fixed in 4.2.6-1)
sid: resolved (fixed in 4.2.6-1)
trixie: resolved (fixed in 4.2.6-1)
Kernel
KVM: VMX: Enable Notify VM exit
kernel_security·2022-05-24·CVSS 4.9
CVE-2015-5307 [MEDIUM] KVM: VMX: Enable Notify VM exit
KVM: VMX: Enable Notify VM exit
There are cases that malicious virtual machines can cause CPU stuck (due
to event windows don't open up), e.g., infinite loop in microcode when
nested #AC (CVE-2015-5307). No event window means no event (NMI, SMI and
IRQ) can be delivered. It leads the CPU to be unavailable to host or
other VMs.
VMM can enable notify VM exit that a VM exit generated if no event
window occurs in VM non-root mode for a specified amount of time (notify
window).
Feature enabling:
- The new vmcs field SECONDARY_EXEC_NOTIFY_VM_EXITING is introduced to
enable this feature. VMM can set NOTIFY_WINDOW vmcs field to adjust
the expected notify window.
- Add a new KVM capability KVM_CAP_X86_NOTIFY_VMEXIT so that user space
can query and enable this feature in per-VM scope. The argumen
GHSA
GHSA-hfhj-gfxm-5x7g: The KVM subsystem in the Linux kernel through 4
ghsa_unreviewed·2022-05-14
CVE-2015-5307 [MEDIUM] GHSA-hfhj-gfxm-5x7g: The KVM subsystem in the Linux kernel through 4
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
OSV
CVE-2015-5307: The KVM subsystem in the Linux kernel through 4
osv·2015-11-16·CVSS 4.9
CVE-2015-5307 [MEDIUM] CVE-2015-5307: The KVM subsystem in the Linux kernel through 4
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
Kernel
KVM: x86: work around infinite loop in microcode when #AC is delivered
kernel_security·2015-11-03·CVSS 4.9
CVE-2015-5307 [MEDIUM] KVM: x86: work around infinite loop in microcode when #AC is delivered
KVM: x86: work around infinite loop in microcode when #AC is delivered
It was found that a guest can DoS a host by triggering an infinite
stream of "alignment check" (#AC) exceptions. This causes the
microcode to enter an infinite loop where the core never receives
another interrupt. The host kernel panics pretty quickly due to the
effects (CVE-2015-5307).
Signed-off-by: Eric Northup
Cc: [email protected]
Signed-off-by: Paolo Bonzini
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5307 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #AC exception [fedora-all]
bugzilla·2015-11-10·CVSS 4.9
CVE-2015-5307 [MEDIUM] CVE-2015-5307 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #AC exception [fedora-all]
CVE-2015-5307 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #AC exception [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2015-5307 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #AC exception [fedora-all]
bugzilla·2015-11-10·CVSS 4.9
CVE-2015-5307 [MEDIUM] CVE-2015-5307 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #AC exception [fedora-all]
CVE-2015-5307 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #AC exception [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
bugzilla·2015-11-02·CVSS 4.9
CVE-2015-5307 [MEDIUM] CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
CVE-2015-5307 virt: guest to host DoS by triggering an infinite loop in microcode via #AC exception
It was found that a guest can DoS a host by triggering an infinite loop in microcode. If a guest in 32-bit mode enabled alignment exceptions, puts the exception handler in ring 3, and then triggers an alignment exception with an unaligned stack, then the microcode will enter an infinite loop. Because there's no instruction boundary the core never receives another interrupt (including SMIs). The host kernel panics pretty quickly due to the effects.
A privileged user inside guest could use this flaw to crash the host kernel
resulting in DoS.
Upstream KVM patch:
-> http://permalink.gmane.org/gmane.linux.kernel/2082329
References:
-> http://www.openwall.com/lists/oss-security/2015/11/10/1
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54a20552e1eae07aa240fa370a0293e006b5faedhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172187.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172300.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172435.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2645.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0046.htmlhttp://support.citrix.com/article/CTX202583http://www.debian.org/security/2015/dsa-3396http://www.debian.org/security/2015/dsa-3414http://www.debian.org/security/2016/dsa-3454http://www.openwall.com/lists/oss-security/2015/11/10/6http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77528http://www.securitytracker.com/id/1034105http://www.ubuntu.com/usn/USN-2800-1http://www.ubuntu.com/usn/USN-2801-1http://www.ubuntu.com/usn/USN-2802-1http://www.ubuntu.com/usn/USN-2803-1http://www.ubuntu.com/usn/USN-2804-1http://www.ubuntu.com/usn/USN-2805-1http://www.ubuntu.com/usn/USN-2806-1http://www.ubuntu.com/usn/USN-2807-1http://xenbits.xen.org/xsa/advisory-156.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1277172https://github.com/torvalds/linux/commit/54a20552e1eae07aa240fa370a0293e006b5faedhttps://kb.juniper.net/JSA10783http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=54a20552e1eae07aa240fa370a0293e006b5faedhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172187.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172300.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172435.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2645.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0046.htmlhttp://support.citrix.com/article/CTX202583http://www.debian.org/security/2015/dsa-3396http://www.debian.org/security/2015/dsa-3414http://www.debian.org/security/2016/dsa-3454http://www.openwall.com/lists/oss-security/2015/11/10/6http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77528http://www.securitytracker.com/id/1034105http://www.ubuntu.com/usn/USN-2800-1http://www.ubuntu.com/usn/USN-2801-1http://www.ubuntu.com/usn/USN-2802-1http://www.ubuntu.com/usn/USN-2803-1http://www.ubuntu.com/usn/USN-2804-1http://www.ubuntu.com/usn/USN-2805-1http://www.ubuntu.com/usn/USN-2806-1http://www.ubuntu.com/usn/USN-2807-1http://xenbits.xen.org/xsa/advisory-156.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1277172https://github.com/torvalds/linux/commit/54a20552e1eae07aa240fa370a0293e006b5faedhttps://kb.juniper.net/JSA10783
2015-11-16
Published