First published: Sun Sep 21 2014(Updated: )
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=3.11.7 | |
Linux Kernel | =3.0-rc1 | |
Linux Kernel | =3.0-rc2 | |
Linux Kernel | =3.0-rc3 | |
Linux Kernel | =3.0-rc4 | |
Linux Kernel | =3.0-rc5 | |
Linux Kernel | =3.0-rc6 | |
Linux Kernel | =3.0-rc7 | |
Linux Kernel | =3.0.1 | |
Linux Kernel | =3.0.2 | |
Linux Kernel | =3.0.3 | |
Linux Kernel | =3.0.4 | |
Linux Kernel | =3.0.5 | |
Linux Kernel | =3.0.6 | |
Linux Kernel | =3.0.7 | |
Linux Kernel | =3.0.8 | |
Linux Kernel | =3.0.9 | |
Linux Kernel | =3.0.10 | |
Linux Kernel | =3.0.11 | |
Linux Kernel | =3.0.12 | |
Linux Kernel | =3.0.13 | |
Linux Kernel | =3.0.14 | |
Linux Kernel | =3.0.15 | |
Linux Kernel | =3.0.16 | |
Linux Kernel | =3.0.17 | |
Linux Kernel | =3.0.18 | |
Linux Kernel | =3.0.19 | |
Linux Kernel | =3.0.20 | |
Linux Kernel | =3.0.21 | |
Linux Kernel | =3.0.22 | |
Linux Kernel | =3.0.23 | |
Linux Kernel | =3.0.24 | |
Linux Kernel | =3.0.25 | |
Linux Kernel | =3.0.26 | |
Linux Kernel | =3.0.27 | |
Linux Kernel | =3.0.28 | |
Linux Kernel | =3.0.29 | |
Linux Kernel | =3.0.30 | |
Linux Kernel | =3.0.31 | |
Linux Kernel | =3.0.32 | |
Linux Kernel | =3.0.33 | |
Linux Kernel | =3.0.34 | |
Linux Kernel | =3.0.35 | |
Linux Kernel | =3.0.36 | |
Linux Kernel | =3.0.37 | |
Linux Kernel | =3.0.38 | |
Linux Kernel | =3.0.39 | |
Linux Kernel | =3.0.40 | |
Linux Kernel | =3.0.41 | |
Linux Kernel | =3.0.42 | |
Linux Kernel | =3.0.43 | |
Linux Kernel | =3.0.44 | |
Linux Kernel | =3.0.45 | |
Linux Kernel | =3.0.46 | |
Linux Kernel | =3.0.47 | |
Linux Kernel | =3.0.48 | |
Linux Kernel | =3.0.49 | |
Linux Kernel | =3.0.50 | |
Linux Kernel | =3.0.51 | |
Linux Kernel | =3.0.52 | |
Linux Kernel | =3.0.53 | |
Linux Kernel | =3.0.54 | |
Linux Kernel | =3.0.55 | |
Linux Kernel | =3.0.56 | |
Linux Kernel | =3.0.57 | |
Linux Kernel | =3.0.58 | |
Linux Kernel | =3.0.59 | |
Linux Kernel | =3.0.60 | |
Linux Kernel | =3.0.61 | |
Linux Kernel | =3.0.62 | |
Linux Kernel | =3.0.63 | |
Linux Kernel | =3.0.64 | |
Linux Kernel | =3.0.65 | |
Linux Kernel | =3.0.66 | |
Linux Kernel | =3.0.67 | |
Linux Kernel | =3.0.68 | |
Linux Kernel | =3.1 | |
Linux Kernel | =3.1-rc1 | |
Linux Kernel | =3.1-rc2 | |
Linux Kernel | =3.1-rc3 | |
Linux Kernel | =3.1-rc4 | |
Linux Kernel | =3.1.1 | |
Linux Kernel | =3.1.2 | |
Linux Kernel | =3.1.3 | |
Linux Kernel | =3.1.4 | |
Linux Kernel | =3.1.5 | |
Linux Kernel | =3.1.6 | |
Linux Kernel | =3.1.7 | |
Linux Kernel | =3.1.8 | |
Linux Kernel | =3.1.9 | |
Linux Kernel | =3.1.10 | |
Linux Kernel | =3.2 | |
Linux Kernel | =3.2-rc2 | |
Linux Kernel | =3.2-rc3 | |
Linux Kernel | =3.2-rc4 | |
Linux Kernel | =3.2-rc5 | |
Linux Kernel | =3.2-rc6 | |
Linux Kernel | =3.2-rc7 | |
Linux Kernel | =3.2.1 | |
Linux Kernel | =3.2.2 | |
Linux Kernel | =3.2.3 | |
Linux Kernel | =3.2.4 | |
Linux Kernel | =3.2.5 | |
Linux Kernel | =3.2.6 | |
Linux Kernel | =3.2.7 | |
Linux Kernel | =3.2.8 | |
Linux Kernel | =3.2.9 | |
Linux Kernel | =3.2.10 | |
Linux Kernel | =3.2.11 | |
Linux Kernel | =3.2.12 | |
Linux Kernel | =3.2.13 | |
Linux Kernel | =3.2.14 | |
Linux Kernel | =3.2.15 | |
Linux Kernel | =3.2.16 | |
Linux Kernel | =3.2.17 | |
Linux Kernel | =3.2.18 | |
Linux Kernel | =3.2.19 | |
Linux Kernel | =3.2.20 | |
Linux Kernel | =3.2.21 | |
Linux Kernel | =3.2.22 | |
Linux Kernel | =3.2.23 | |
Linux Kernel | =3.2.24 | |
Linux Kernel | =3.2.25 | |
Linux Kernel | =3.2.26 | |
Linux Kernel | =3.2.27 | |
Linux Kernel | =3.2.28 | |
Linux Kernel | =3.2.29 | |
Linux Kernel | =3.2.30 | |
Linux Kernel | =3.3 | |
Linux Kernel | =3.3-rc1 | |
Linux Kernel | =3.3-rc2 | |
Linux Kernel | =3.3-rc3 | |
Linux Kernel | =3.3-rc4 | |
Linux Kernel | =3.3-rc5 | |
Linux Kernel | =3.3-rc6 | |
Linux Kernel | =3.3-rc7 | |
Linux Kernel | =3.3.1 | |
Linux Kernel | =3.3.2 | |
Linux Kernel | =3.3.3 | |
Linux Kernel | =3.3.4 | |
Linux Kernel | =3.3.5 | |
Linux Kernel | =3.3.6 | |
Linux Kernel | =3.3.7 | |
Linux Kernel | =3.3.8 | |
Linux Kernel | =3.4 | |
Linux Kernel | =3.4-rc1 | |
Linux Kernel | =3.4-rc2 | |
Linux Kernel | =3.4-rc3 | |
Linux Kernel | =3.4-rc4 | |
Linux Kernel | =3.4-rc5 | |
Linux Kernel | =3.4-rc6 | |
Linux Kernel | =3.4-rc7 | |
Linux Kernel | =3.4.1 | |
Linux Kernel | =3.4.2 | |
Linux Kernel | =3.4.3 | |
Linux Kernel | =3.4.4 | |
Linux Kernel | =3.4.5 | |
Linux Kernel | =3.4.6 | |
Linux Kernel | =3.4.7 | |
Linux Kernel | =3.4.8 | |
Linux Kernel | =3.4.9 | |
Linux Kernel | =3.4.10 | |
Linux Kernel | =3.4.11 | |
Linux Kernel | =3.4.12 | |
Linux Kernel | =3.4.13 | |
Linux Kernel | =3.4.14 | |
Linux Kernel | =3.4.15 | |
Linux Kernel | =3.4.16 | |
Linux Kernel | =3.4.17 | |
Linux Kernel | =3.4.18 | |
Linux Kernel | =3.4.19 | |
Linux Kernel | =3.4.20 | |
Linux Kernel | =3.4.21 | |
Linux Kernel | =3.4.22 | |
Linux Kernel | =3.4.23 | |
Linux Kernel | =3.4.24 | |
Linux Kernel | =3.4.25 | |
Linux Kernel | =3.4.26 | |
Linux Kernel | =3.4.27 | |
Linux Kernel | =3.4.28 | |
Linux Kernel | =3.4.29 | |
Linux Kernel | =3.4.30 | |
Linux Kernel | =3.4.31 | |
Linux Kernel | =3.4.32 | |
Linux Kernel | =3.5.1 | |
Linux Kernel | =3.5.2 | |
Linux Kernel | =3.5.3 | |
Linux Kernel | =3.5.4 | |
Linux Kernel | =3.5.5 | |
Linux Kernel | =3.5.6 | |
Linux Kernel | =3.5.7 | |
Linux Kernel | =3.6 | |
Linux Kernel | =3.6.1 | |
Linux Kernel | =3.6.2 | |
Linux Kernel | =3.6.3 | |
Linux Kernel | =3.6.4 | |
Linux Kernel | =3.6.5 | |
Linux Kernel | =3.6.6 | |
Linux Kernel | =3.6.7 | |
Linux Kernel | =3.6.8 | |
Linux Kernel | =3.6.9 | |
Linux Kernel | =3.6.10 | |
Linux Kernel | =3.6.11 | |
Linux Kernel | =3.7 | |
Linux Kernel | =3.7.1 | |
Linux Kernel | =3.7.2 | |
Linux Kernel | =3.7.3 | |
Linux Kernel | =3.7.4 | |
Linux Kernel | =3.7.5 | |
Linux Kernel | =3.7.6 | |
Linux Kernel | =3.7.7 | |
Linux Kernel | =3.7.8 | |
Linux Kernel | =3.7.9 | |
Linux Kernel | =3.7.10 | |
Linux Kernel | =3.8.0 | |
Linux Kernel | =3.8.1 | |
Linux Kernel | =3.8.2 | |
Linux Kernel | =3.8.3 | |
Linux Kernel | =3.8.4 | |
Linux Kernel | =3.8.5 | |
Linux Kernel | =3.8.6 | |
Linux Kernel | =3.8.7 | |
Linux Kernel | =3.8.8 | |
Linux Kernel | =3.8.9 | |
Linux Kernel | =3.8.10 | |
Linux Kernel | =3.8.11 | |
Linux Kernel | =3.8.12 | |
Linux Kernel | =3.8.13 | |
Linux Kernel | =3.9-rc1 | |
Linux Kernel | =3.9-rc2 | |
Linux Kernel | =3.9-rc3 | |
Linux Kernel | =3.9-rc4 | |
Linux Kernel | =3.9-rc5 | |
Linux Kernel | =3.9-rc6 | |
Linux Kernel | =3.9-rc7 | |
Linux Kernel | =3.9.0 | |
Linux Kernel | =3.9.1 | |
Linux Kernel | =3.9.2 | |
Linux Kernel | =3.9.3 | |
Linux Kernel | =3.9.4 | |
Linux Kernel | =3.9.5 | |
Linux Kernel | =3.9.6 | |
Linux Kernel | =3.9.7 | |
Linux Kernel | =3.9.8 | |
Linux Kernel | =3.9.9 | |
Linux Kernel | =3.9.10 | |
Linux Kernel | =3.9.11 | |
Linux Kernel | =3.10.1 | |
Linux Kernel | =3.10.2 | |
Linux Kernel | =3.10.3 | |
Linux Kernel | =3.10.4 | |
Linux Kernel | =3.10.5 | |
Linux Kernel | =3.10.6 | |
Linux Kernel | =3.10.7 | |
Linux Kernel | =3.10.8 | |
Linux Kernel | =3.10.9 | |
Linux Kernel | =3.10.10 | |
Linux Kernel | =3.10.11 | |
Linux Kernel | =3.10.12 | |
Linux Kernel | =3.10.13 | |
Linux Kernel | =3.10.14 | |
Linux Kernel | =3.10.15 | |
Linux Kernel | =3.10.16 | |
Linux Kernel | =3.10.17 | |
Linux Kernel | =3.10.18 | |
Linux Kernel | =3.11 | |
Linux Kernel | =3.11.1 | |
Linux Kernel | =3.11.2 | |
Linux Kernel | =3.11.3 | |
Linux Kernel | =3.11.4 | |
Linux Kernel | =3.11.5 | |
Linux Kernel | =3.11.6 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3645 has a medium severity rating due to its potential to cause denial of service through guest OS crashes.
To fix CVE-2014-3645, upgrade to a Linux kernel version higher than 3.11.7 or apply the relevant patches provided by your distribution.
Systems running Linux kernel versions before 3.12, particularly those with INVEPT instruction support, are vulnerable to CVE-2014-3645.
CVE-2014-3645 does not allow remote attacks as it requires a crafted application to be run in the guest OS.
CVE-2014-3645 is less of a concern on updated systems, but organizations should ensure all kernels are up to date to mitigate any possible risks.