Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian 3.2.63-2+deb7u1 Critical: Kernel Denial Of Service Issues

debian
Calendar Grey October 31, 2014
Debian Logo
The Debian advisory DSA-3060-2 addresses kernel security loopholes posing denial of service threats. Immediate updating is advised.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service: CVE-2014-3610

Summary

CVE-2014-3610

Lars Bull of Google and Nadav Amit reported a flaw in how KVM
handles noncanonical writes to certain MSR registers. A privileged
guest user can exploit this flaw to cause a denial of service
(kernel panic) on the host.

CVE-2014-3611

Lars Bull of Google reported a race condition in in the PIT
emulation code in KVM. A local guest user with access to PIT i/o
ports could exploit this flaw to cause a denial of service (crash)
on the host.

CVE-2014-3645 / CVE-2014-3646

The Advanced Threat Research team at Intel Security discovered
that the KVM subsystem did not handle the VM exits gracefully
for the invept (Invalidate Translations Derived from EPT) and
invvpid (Invalidate Translations Based on VPID) instructions. On
hosts with an Intel processor and invept/invppid VM exit
support, an unprivileged guest user could use these instructions
to crash the guest.

CVE-2014-3647

Nadav Amit reported that KVM mishandles noncanonical addresses...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2014-3610 CVE-2014-3611 CVE-2014-3645 CVE-2014-3646

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here