CVE-2015-8104Infinite Loop in Kernel

Severity
10.0CRITICALNVD
NVD5.5OSV4.9
EPSS
0.3%
top 44.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateJan 5

Description

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages8 packages

Debianlinux/linux_kernel< 4.2.6-2+3
Ubuntulinux/linux_kernel< 3.13.0-73.116
NVDxen/xen4.5.04.14.0+18
Alpinexen/xen< 4.15.5-r3+8

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 15.04

Patches

🔴Vulnerability Details

16
OSV
CVE-2023-34328: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE2024-01-05
OSV
CVE-2023-34327: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE2024-01-05
OSV
CVE-2023-34328: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE2024-01-05
GHSA
GHSA-7fx2-c8rv-2w4f: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE2024-01-05
CVEList
x86/AMD: Debug Mask handling2024-01-05

📋Vendor Advisories

12
Debian
CVE-2023-34328: xen - [This CNA information record relates to multiple CVEs; the text explains which a...2023
Debian
CVE-2023-34327: xen - [This CNA information record relates to multiple CVEs; the text explains which a...2023
Ubuntu
Linux kernel (Wily HWE) vulnerabilities2015-12-17
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities2015-12-17
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2015-12-17

💬Community

3
Bugzilla
CVE-2015-8104 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]2015-11-10
Bugzilla
CVE-2015-8104 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]2015-11-10
Bugzilla
CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception2015-11-05
CVE-2015-8104 — Infinite Loop in Linux Kernel | cvebase