CVE-2015-8104
published 2015-11-16CVE-2015-8104: The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by…
PriorityP350critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
2.50%
82.9th percentile
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.2.6-2 (bookworm) | linux 4.2.6-2 (bookworm) |
| debian | virtualbox | < linux 4.2.6-2 (bookworm) | linux 4.2.6-2 (bookworm) |
| debian | xen | < linux 4.2.6-2 (bookworm) | linux 4.2.6-2 (bookworm) |
| debian | xen | < xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm) | xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm) |
| linux | linux_kernel | <= 4.2.3 | — |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 3.13.0-73.116 | 3.13.0-73.116 |
| oracle | solaris | — | — |
| oracle | vm_virtualbox | 4.0.0 – 4.0.34 | — |
| oracle | vm_virtualbox | 4.1.0 – 4.1.42 | — |
| oracle | vm_virtualbox | 4.2.0 – 4.2.34 | — |
| oracle | vm_virtualbox | 4.3.0 – 4.3.35 | — |
| oracle | vm_virtualbox | 5.0.0 – 5.0.13 | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-34328: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
vendor_debian·2023·CVSS 10.0
CVE-2023-34328 [CRITICAL] CVE-2023-34328: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
Scope: local
bookworm: resolved (fixed in 4.17.2+76-ge1f9cb16e2-1~deb12u1)
bullseye: open
forky: resolved (fixed in 4.17.2+55-g0b56bed864-1)
sid: resolved (fixed in 4.17.2+55-g0b56bed8
Debian
CVE-2023-34327: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
vendor_debian·2023·CVSS 10.0
CVE-2023-34327 [CRITICAL] CVE-2023-34327: xen - [This CNA information record relates to multiple CVEs; the text explains which a...
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
Scope: local
bookworm: resolved (fixed in 4.17.2+76-ge1f9cb16e2-1~deb12u1)
bullseye: open
forky: resolved (fixed in 4.17.2+55-g0b56bed864-1)
sid: resolved (fixed in 4.17.2+55-g0b56bed8
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this t
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the virtual video osd test driver in the Linux
kernel did not properly initialize data structures. A local attacker could
use this to obtain sensiti
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 2.1
CVE-2015-7872 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the virtual video osd test driver in the Linux
kernel did not properly initialize data structures. A local attacker could
use this to obtain sensitive informati
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-12-17·CVSS 4.9
CVE-2015-7799 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive information fr
Red Hat
virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
vendor_redhat·2015-11-10·CVSS 10.0
CVE-2015-8104 [CRITICAL] CWE-835 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
It was found that the x86 ISA (Instruction Set Architecture) is prone to a denial of service attack inside a virtualized environment in the form of an infinite loop in the microcode due to the way (sequential) delivering of benign exceptions such as #DB (debug exception) is handled. A privileged user inside a guest could use this flaw to create denial of service conditions on the host kernel.
Statement: This issue affects the version of the kvm & xen packages as shipped with Red Hat E
Debian
CVE-2015-8104: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x...
vendor_debian·2015·CVSS 10.0
CVE-2015-8104 [CRITICAL] CVE-2015-8104: linux - The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x...
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
Scope: local
bookworm: resolved (fixed in 4.2.6-2)
bullseye: resolved (fixed in 4.2.6-2)
forky: resolved (fixed in 4.2.6-2)
sid: resolved (fixed in 4.2.6-2)
trixie: resolved (fixed in 4.2.6-2)
OSV
CVE-2023-34328: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
osv·2024-01-05·CVSS 10.0
CVE-2023-34328 [CRITICAL] CVE-2023-34328: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
AMD CPUs since ~2014 have extensions to normal x86 debugging functionality.
Xen supports guests using these extensions.
Unfortunately there are errors in Xen's handling of the guest state, leading
to denials of service.
1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of
a previous vCPUs debug mask state.
2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.
This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock
up the CPU entirely.
OSV
CVE-2023-34327: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE
osv·2024-01-05·CVSS 10.0
CVE-2023-34327 [CRITICAL] CVE-2023-34327: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
OSV
CVE-2023-34328: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE
osv·2024-01-05·CVSS 10.0
CVE-2023-34328 [CRITICAL] CVE-2023-34328: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
GHSA
GHSA-7fx2-c8rv-2w4f: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
ghsa_unreviewed·2024-01-05·CVSS 10.0
CVE-2023-34327 [CRITICAL] GHSA-7fx2-c8rv-2w4f: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
AMD CPUs since ~2014 have extensions to normal x86 debugging functionality.
Xen supports guests using these extensions.
Unfortunately there are errors in Xen's handling of the guest state, leading
to denials of service.
1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of
a previous vCPUs debug mask state.
2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.
This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock
up the CPU entirely.
OSV
CVE-2023-34327: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
osv·2024-01-05·CVSS 10.0
CVE-2023-34327 [CRITICAL] CVE-2023-34327: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
AMD CPUs since ~2014 have extensions to normal x86 debugging functionality.
Xen supports guests using these extensions.
Unfortunately there are errors in Xen's handling of the guest state, leading
to denials of service.
1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of
a previous vCPUs debug mask state.
2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.
This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock
up the CPU entirely.
GHSA
GHSA-fm4g-p248-j5wj: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
ghsa_unreviewed·2024-01-05·CVSS 10.0
CVE-2023-34328 [CRITICAL] GHSA-fm4g-p248-j5wj: [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE
[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
AMD CPUs since ~2014 have extensions to normal x86 debugging functionality.
Xen supports guests using these extensions.
Unfortunately there are errors in Xen's handling of the guest state, leading
to denials of service.
1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of
a previous vCPUs debug mask state.
2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.
This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock
up the CPU entirely.
GHSA
GHSA-878r-5qjm-6859: The KVM subsystem in the Linux kernel through 4
ghsa_unreviewed·2022-05-14
CVE-2015-8104 [MEDIUM] GHSA-878r-5qjm-6859: The KVM subsystem in the Linux kernel through 4
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
OSV
linux vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive information from the kernel. (CVE-2015-7885)
OSV
linux-lts-utopic vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the driver for Digi Neo and ClassicBoard devices did
not properly initialize data structures. A local attacker could use this to
obtain sensitive information from the kernel. (CVE-2015-7885)
OSV
linux-lts-wily vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted
to garbage collect incompletely instantiated keys. A local unprivileged
attacker could use this to cause a denial of service (system crash).
(CVE-2015-7872)
It was discover
OSV
linux-lts-vivid vulnerabilities
osv·2015-12-17·CVSS 4.9
CVE-2015-8104 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Jan Beulich discovered that the KVM svm hypervisor implementation in the
Linux kernel did not properly catch Debug exceptions on AMD processors. An
attacker in a guest virtual machine could use this to cause a denial of
service (system crash) in the host OS. (CVE-2015-8104)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp could cause a denial of service
(system crash). (CVE-2015-7799)
It was discovered that the virtual video osd test driver in the Linux
kernel did not properly initialize data structures. A local attacker could
use this to obtain sensitive information from the kernel. (CVE-2015-7884)
It was discovered that the
OSV
CVE-2015-8104: The KVM subsystem in the Linux kernel through 4
osv·2015-11-16·CVSS 10.0
CVE-2015-8104 [CRITICAL] CVE-2015-8104: The KVM subsystem in the Linux kernel through 4
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
Kernel
KVM: svm: unconditionally intercept #DB
kernel_security·2015-11-10·CVSS 10.0
CVE-2015-8104 [CRITICAL] KVM: svm: unconditionally intercept #DB
KVM: svm: unconditionally intercept #DB
This is needed to avoid the possibility that the guest triggers
an infinite stream of #DB exceptions (CVE-2015-8104).
VMX is not affected: because it does not save DR6 in the VMCS,
it already intercepts #DB unconditionally.
Reported-by: Jan Beulich
Cc: [email protected]
Signed-off-by: Paolo Bonzini
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8104 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]
bugzilla·2015-11-10·CVSS 10.0
CVE-2015-8104 [CRITICAL] CVE-2015-8104 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]
CVE-2015-8104 kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2015-8104 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]
bugzilla·2015-11-10·CVSS 10.0
CVE-2015-8104 [CRITICAL] CVE-2015-8104 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]
CVE-2015-8104 xen: kernel: kvm: guest to host DoS by triggering an infinite loop in microcode via #DB exception [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
bugzilla·2015-11-05·CVSS 10.0
CVE-2015-8104 [CRITICAL] CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
CVE-2015-8104 virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception
It was found that a malicious HVM guest administrator can cause DoS, specifically prevent use of physical CPU for significant, perhaps indefinite period. When a benign exception occurs while delivering another benign exception, it is architecturally specified that these would be delivered sequentially. There are, however, cases where this results in an infinite loop inside the CPU, which (in the virtualized case) can be broken only by intercepting delivery of the respective exception.
When a guest sets up a hardware breakpoint covering a data structure involved in delivering #DB (Debug Exception), upon completion of the delivery of the first exception another #DB will need to be delivered.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cbdb967af3d54993f5814f1cee0ed311a055377dhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172187.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172300.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172435.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2645.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0046.htmlhttp://support.citrix.com/article/CTX202583http://support.citrix.com/article/CTX203879http://www.debian.org/security/2015/dsa-3414http://www.debian.org/security/2015/dsa-3426http://www.debian.org/security/2016/dsa-3454http://www.openwall.com/lists/oss-security/2015/11/10/5http://www.openwall.com/lists/oss-security/2023/10/10/4http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77524http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034105http://www.ubuntu.com/usn/USN-2840-1http://www.ubuntu.com/usn/USN-2841-1http://www.ubuntu.com/usn/USN-2841-2http://www.ubuntu.com/usn/USN-2842-1http://www.ubuntu.com/usn/USN-2842-2http://www.ubuntu.com/usn/USN-2843-1http://www.ubuntu.com/usn/USN-2843-2http://www.ubuntu.com/usn/USN-2844-1http://xenbits.xen.org/xsa/advisory-156.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1278496https://github.com/torvalds/linux/commit/cbdb967af3d54993f5814f1cee0ed311a055377dhttps://kb.juniper.net/JSA10783http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cbdb967af3d54993f5814f1cee0ed311a055377dhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172187.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172300.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172435.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2636.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2645.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0046.htmlhttp://support.citrix.com/article/CTX202583http://support.citrix.com/article/CTX203879http://www.debian.org/security/2015/dsa-3414http://www.debian.org/security/2015/dsa-3426http://www.debian.org/security/2016/dsa-3454http://www.openwall.com/lists/oss-security/2015/11/10/5http://www.openwall.com/lists/oss-security/2023/10/10/4http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77524http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034105http://www.ubuntu.com/usn/USN-2840-1http://www.ubuntu.com/usn/USN-2841-1http://www.ubuntu.com/usn/USN-2841-2http://www.ubuntu.com/usn/USN-2842-1http://www.ubuntu.com/usn/USN-2842-2http://www.ubuntu.com/usn/USN-2843-1http://www.ubuntu.com/usn/USN-2843-2http://www.ubuntu.com/usn/USN-2844-1http://xenbits.xen.org/xsa/advisory-156.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1278496https://github.com/torvalds/linux/commit/cbdb967af3d54993f5814f1cee0ed311a055377dhttps://kb.juniper.net/JSA10783
2015-11-16
Published