CVE-2014-3601

Published Sep 1, 2014

Last updated 2 years ago

Overview

Description
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
6.9
Exploitability score
2.5
Vector string
AV:A/AC:H/Au:S/C:N/I:N/A:C

Weaknesses

nvd@nist.gov
CWE-189

Social media

Hype score
Not currently trending

Configurations