Vulnerability Description
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.12, < 3.2.69 |
| Canonical | Ubuntu Linux | 10.04 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152747.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0674.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0695.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0726.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0751.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0782.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0783.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0803.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0870.htmlThird Party Advisory
FAQ
What is CVE-2014-8159?
CVE-2014-8159 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regio...
How severe is CVE-2014-8159?
CVE-2014-8159 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8159?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Canonical Ubuntu Linux, Debian Debian Linux.