Lucene search

K
f5F5F5:K13145361
HistoryJan 27, 2016 - 12:00 a.m.

K13145361 : Linux kernel KVM subsystem vulnerability CVE-2014-3647

2016-01-2700:00:00
my.f5.com
18

5.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.0%

Security Advisory Description

arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. (CVE-2014-3647)
Impact
A local user with Advanced Shell (bash) access on a vCMP guest may be able to exploit this vulnerability to cause a denial of service (DoS) for the vCMP guest (only the vCMP guest). The vCMP Host/Hypervisor is not impacted by this vulnerability.Important: Standard Non-vCMP deployments are not vulnerable. Only deployments using vCMP guests are vulnerable.