CVE Database
/

CVE-2014-8159

Back to search

CVE-2014-8159

Published: Mar 16, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2015:0783
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2015:1491
vendor-advisory
x_refsource_SUSE
USN-2529-1
vendor-advisory
x_refsource_UBUNTU
USN-2530-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0695
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2015:1489
vendor-advisory
x_refsource_SUSE
SUSE-SU-2015:1488
vendor-advisory
x_refsource_SUSE
USN-2561-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0751
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0803
vendor-advisory
x_refsource_REDHAT
DSA-3237
vendor-advisory
x_refsource_DEBIAN
USN-2528-1
vendor-advisory
x_refsource_UBUNTU
USN-2527-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0919
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0782
vendor-advisory
x_refsource_REDHAT
USN-2526-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2015:1478
vendor-advisory
x_refsource_SUSE
FEDORA-2015-4066
vendor-advisory
x_refsource_FEDORA
1032224
vdb-entry
x_refsource_SECTRACK
73060
vdb-entry
x_refsource_BID
USN-2525-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0870
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2015:1487
vendor-advisory
x_refsource_SUSE
RHSA-2015:0726
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0674
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now