Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8104

Опубликовано: 10 нояб. 2015
Источник: redhat
CVSS2: 5.2
EPSS Низкий

Описание

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

It was found that the x86 ISA (Instruction Set Architecture) is prone to a denial of service attack inside a virtualized environment in the form of an infinite loop in the microcode due to the way (sequential) delivering of benign exceptions such as #DB (debug exception) is handled. A privileged user inside a guest could use this flaw to create denial of service conditions on the host kernel.

Отчет

This issue affects the version of the kvm & xen packages as shipped with Red Hat Enterprise Linux 5. This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2. This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and 7. Future kernel updates for the respective releases may address this issue. Red Hat Enterprise Linux 5 is now in Production Phase 3 of the support and maintenance life cycle. Thus it is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 5kvmWill not fix
Red Hat Enterprise Linux 5xenWill not fix
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2015:263615.12.2015
Red Hat Enterprise Linux 6.2 Advanced Update SupportkernelFixedRHSA-2016:004619.01.2016
Red Hat Enterprise Linux 6.4 Advanced Update SupportkernelFixedRHSA-2016:000407.01.2016
Red Hat Enterprise Linux 6.5 Advanced Update SupportkernelFixedRHSA-2015:264515.12.2015
Red Hat Enterprise Linux 6.6 Extended Update SupportkernelFixedRHSA-2016:002412.01.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1278496virt: guest to host DoS by triggering an infinite loop in microcode via #DB exception

EPSS

Процентиль: 60%
0.00401
Низкий

5.2 Medium

CVSS2

Связанные уязвимости

CVSS3: 10
ubuntu
больше 9 лет назад

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

CVSS3: 10
nvd
больше 9 лет назад

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

CVSS3: 10
debian
больше 9 лет назад

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x thr ...

CVSS3: 10
github
около 3 лет назад

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

fstec
больше 9 лет назад

Уязвимость гипервизора Xen, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 60%
0.00401
Низкий

5.2 Medium

CVSS2