CVE-2016-5412
published 2016-08-06CVE-2016-5412: arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to…
PriorityP423medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.34%
27.1th percentile
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.7.2-1 (bookworm) | linux 4.7.2-1 (bookworm) |
| linux | linux_kernel | <= 4.7 | — |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.7.2-1 | 4.7.2-1 |
| linux | linux_kernel | >= 0 < 4.4.0-38.57 | 4.4.0-38.57 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ccw5-jvc3-prf4: arch/powerpc/kvm/book3s_hv_rmhandlers
ghsa_unreviewed·2022-05-14
CVE-2016-5412 [MEDIUM] GHSA-ccw5-jvc3-prf4: arch/powerpc/kvm/book3s_hv_rmhandlers
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
OSV
linux-raspi2 vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux-raspi2 vulnerabilities
linux-raspi2 vulnerabilities
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
OSV
linux vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
OSV
linux-snapdragon vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux-snapdragon vulnerabilities
linux-snapdragon vulnerabilities
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
OSV
linux-lts-xenial vulnerabilities
osv·2016-09-19·CVSS 6.5
CVE-2016-6136 [MEDIUM] linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3084-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller dev
OSV
CVE-2016-5412: arch/powerpc/kvm/book3s_hv_rmhandlers
osv·2016-08-06·CVSS 6.5
CVE-2016-5412 [MEDIUM] CVE-2016-5412: arch/powerpc/kvm/book3s_hv_rmhandlers
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
Kernel
Merge branch 'kvm-ppc-next' of git://git.kernel.org/pub/scm/linux/kernel/git/paulus/powerpc into next
kernel_security·2016-08-01·CVSS 6.5
CVE-2016-5412 [MEDIUM] Merge branch 'kvm-ppc-next' of git://git.kernel.org/pub/scm/linux/kernel/git/paulus/powerpc into next
Merge branch 'kvm-ppc-next' of git://git.kernel.org/pub/scm/linux/kernel/git/paulus/powerpc into next
Fix for CVE-2016-5412, a denial-of-service vulnerability in HV KVM on
POWER8 machines
Kernel
KVM: PPC: Book3S HV: Save/restore TM state in H_CEDE
kernel_security·2016-06-22·CVSS 6.5
CVE-2016-5412 [MEDIUM] KVM: PPC: Book3S HV: Save/restore TM state in H_CEDE
KVM: PPC: Book3S HV: Save/restore TM state in H_CEDE
It turns out that if the guest does a H_CEDE while the CPU is in
a transactional state, and the H_CEDE does a nap, and the nap
loses the architected state of the CPU (which is is allowed to do),
then we lose the checkpointed state of the virtual CPU. In addition,
the transactional-memory state recorded in the MSR gets reset back
to non-transactional, and when we try to return to the guest, we take
a TM bad thing type of program interrupt because we are trying to
transition from non-transactional to transactional with a hrfid
instruction, which is not permitted.
The result of the program interrupt occurring at that point is that
the host CPU will hang in an infinite loop with interrupts disabled.
Thus this is a denial of service vulnera
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
Instruct
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
USN-3084-1 fixed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengf
Ubuntu
Linux kernel (Qualcomm Snapdragon) vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel (Qualcomm Snapdragon) vulnerabilities
Title: Linux kernel (Qualcomm Snapdragon) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
Ins
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-09-19·CVSS 6.5
CVE-2016-5412 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pengfei Wang discovered a race condition in the audit subsystem in the
Linux kernel. A local attacker could use this to corrupt audit logs or
disrupt system-call auditing. (CVE-2016-6136)
It was discovered that the powerpc and powerpc64 hypervisor-mode KVM
implementation in the Linux kernel for did not properly maintain state
about transactional memory. An unprivileged attacker in a guest could cause
a denial of service (CPU lockup) in the host OS. (CVE-2016-5412)
Pengfei Wang discovered a race condition in the Chrome OS embedded
controller device driver in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash). (CVE-2016-6156)
Instructions: After a sta
Red Hat
Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode
vendor_redhat·2016-07-28·CVSS 6.5
CVE-2016-5412 [MEDIUM] CWE-835 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode
Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
Statement: This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
This issue affects the version of the kernel packages as shipped with
Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterprise Linux 7 may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Li
Debian
CVE-2016-5412: linux - arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on Power...
vendor_debian·2016·CVSS 6.5
CVE-2016-5412 [MEDIUM] CVE-2016-5412: linux - arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on Power...
arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: resolved (fixed in 4.7.2-1)
forky: resolved (fixed in 4.7.2-1)
sid: resolved (fixed in 4.7.2-1)
trixie: resolved (fixed in 4.7.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5412 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode [fedora-all]
bugzilla·2016-07-28·CVSS 6.5
CVE-2016-5412 [MEDIUM] CVE-2016-5412 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode [fedora-all]
CVE-2016-5412 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2016-5412 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode
bugzilla·2016-06-24·CVSS 6.5
CVE-2016-5412 [MEDIUM] CVE-2016-5412 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode
CVE-2016-5412 Kernel: powerpc: kvm: Infinite loop via H_CEDE hypercall when running under hypervisor-mode
It was reported that when a guest kernel running under hypervisor-mode KVM (i.e. "HV KVM" rather than "PR KVM"), does the H_CEDE hypercall while a suspended transaction exists, the host CPU may, under certain circumstances, hang in an infinite loop with interrupts disabled. To trigger this, it is necessary to have the guest using an SMT mode of at least 2, with another thread in the same core busy at the time that the H_CEDE is done. The other thread doesn't need to be using transactional memory.
Upstream patches:
-> https://marc.info/?l=kvm&m=146968629127349&w=2
Discussion:
Created attachment 1171980
Patch 1
---
Created attachment 1171981
Patch 2
---
Created kernel tracking bu
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=93d17397e4e2182fdaad503e2f9da46202c0f1c3http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f024ee098476a3e620232e4a78cfac505f121245http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://www.openwall.com/lists/oss-security/2016/07/28/2https://bugzilla.redhat.com/show_bug.cgi?id=1349916https://github.com/torvalds/linux/commit/93d17397e4e2182fdaad503e2f9da46202c0f1c3https://github.com/torvalds/linux/commit/f024ee098476a3e620232e4a78cfac505f121245http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=93d17397e4e2182fdaad503e2f9da46202c0f1c3http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f024ee098476a3e620232e4a78cfac505f121245http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://www.openwall.com/lists/oss-security/2016/07/28/2https://bugzilla.redhat.com/show_bug.cgi?id=1349916https://github.com/torvalds/linux/commit/93d17397e4e2182fdaad503e2f9da46202c0f1c3https://github.com/torvalds/linux/commit/f024ee098476a3e620232e4a78cfac505f121245
2016-08-06
Published