Lucene search

K
cve[email protected]CVE-2014-8159
HistoryMar 16, 2015 - 10:59 a.m.

CVE-2014-8159

2015-03-1610:59:01
CWE-264
web.nvd.nist.gov
90
infiniband
linux kernel
cve-2014-8159
memory access vulnerability
nvd
security vulnerability

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

Affected configurations

NVD
Node
linuxlinux_kernelRange2.6.123.2.69
OR
linuxlinux_kernelRange3.33.4.108
OR
linuxlinux_kernelRange3.53.10.75
OR
linuxlinux_kernelRange3.113.12.41
OR
linuxlinux_kernelRange3.133.14.39
OR
linuxlinux_kernelRange3.153.16.35
OR
linuxlinux_kernelRange3.173.18.13
OR
linuxlinux_kernelRange3.193.19.5
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch12.04-
OR
canonicalubuntu_linuxMatch14.04esm
OR
canonicalubuntu_linuxMatch14.10
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0

References

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%