CVE-2014-3647: Medium severity linux kernel vulnerability
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Other sources
kvm currently mishandles noncanonical addresses when emulating instructions that change rip (eg branches, calls), potentially causing a failed VM-entry.
A guest user with access to I/O or MMIO region can use this flaw to crash the guest.
Acknowledgements:
Red Hat would like to thank Nadav Amit for reporting this issue.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3647?
CVE-2014-3647 is categorized as a denial of service vulnerability that can lead to a guest OS crash.
How do I fix CVE-2014-3647?
To fix CVE-2014-3647, update the Linux kernel to a version that includes the security patch, such as 5.10.223-1 or newer.
Which systems are affected by CVE-2014-3647?
CVE-2014-3647 affects Linux kernel versions up to 3.17.2 and various distributions including Debian, Ubuntu, Red Hat, and SUSE.
Can CVE-2014-3647 be exploited remotely?
CVE-2014-3647 can be exploited by users of a guest OS to cause a denial of service, but it requires local access to the virtual machine.
What are the consequences of CVE-2014-3647?
The exploitation of CVE-2014-3647 can lead to a denial of service, causing instability or crashes in the guest operating system.