UBUNTU-CVE-2014-0049
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-0049
UBUNTU-CVE-2014-0049
Summary:
Details: Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that triggers an invalid memory copy affecting certain cancel_work_item data.
References: https://ubuntu.com/security/CVE-2014-0049, http://seclists.org/oss-sec/2014/q1/468, https://ubuntu.com/security/notices/USN-2175-1, https://ubuntu.com/security/notices/USN-2176-1, https://ubuntu.com/security/notices/USN-2177-1, https://ubuntu.com/security/notices/USN-2178-1, https://ubuntu.com/security/notices/USN-2179-1, https://ubuntu.com/security/notices/USN-2180-1, https://ubuntu.com/security/notices/USN-2181-1, https://www.cve.org/CVERecord?id=CVE-2014-0049
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
