Linux Kernel KVM DoS Vulnerability (CVE-2014-8480)
Release date:
Updated on:
Affected Systems:
Linux kernel
Description:
Bugtraq id: 70710
CVE (CAN) ID: CVE-2014-8480
Linux Kernel is the Kernel of the Linux operating system.
The command decoding module of Linux Kernel 3.17 has the DoS vulnerability caused by an error. Remote attackers can use special RIP-relative commands ("prefetch", "hint-nop", and "clflush" commands) to launch DoS attacks.
<* Source: Nadav Amit
*>
Suggestion:
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org/cgit/virt/kvm/kvm.git/commit? Id = 13e457e0eebf0a0c82c38ceb890d93eb826d62a6
Http://git.kernel.org/cgit/virt/kvm/kvm.git/commit? Id = 3f6f1480d86bf9fc16c160d803ab1d006e3058d5
The Ubuntu 13.10 (Saucy Salamander) Kernel has been upgraded to Linux Kernel 3.10 RC5
Linux Kernel 3.4.62 LTS is now available for download
How to install Linux kernel 13.10 On Ubuntu 3.12
Linux Kernel: click here
Linux Kernel: click here
This article permanently updates the link address: