UBUNTU-CVE-2014-3601
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3601
UBUNTU-CVE-2014-3601
Summary:
Details: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
References: https://ubuntu.com/security/CVE-2014-3601, https://git.kernel.org/cgit/virt/kvm/kvm.git/commit/?id=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7, https://ubuntu.com/security/notices/USN-2356-1, https://ubuntu.com/security/notices/USN-2357-1, https://ubuntu.com/security/notices/USN-2358-1, https://ubuntu.com/security/notices/USN-2359-1, https://www.cve.org/CVERecord?id=CVE-2014-3601
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
