CVE-2014-8159: Integer Overflow
It was found that the Linux kernel's Infiniband subsystem did not properly sanitize input parameters while registering memory regions from the userspace via the (u)verbs API. As a result, an unrestricted physical memory access could be achieved.
A local user with access to /dev/infiniband/uverbsX could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Other sources
It was found that the Linux kernel's Infiniband subsystem did not properly sanitize input parameters while registering memory regions from user space via the (u)verbs API. A local user with access to a /dev/infiniband/uverbsX device could use this flaw to crash the system or, potentially, escalate their privileges on the system.
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-8159?
CVE-2014-8159 has a severity rating that indicates it may allow local users to gain unrestricted access to physical memory.
How do I fix CVE-2014-8159?
To fix CVE-2014-8159, update the Linux kernel to the recommended versions provided by your operating system vendor.
Which Linux distributions are affected by CVE-2014-8159?
CVE-2014-8159 affects various Linux distributions including Red Hat Enterprise Linux and specific kernel versions.
What is the impact of CVE-2014-8159 on system security?
The impact of CVE-2014-8159 on system security includes the potential for local users to exploit the vulnerability to access sensitive information.
Who is at risk from CVE-2014-8159?
Local users with access to the affected systems and kernel versions are at risk from CVE-2014-8159.