CVE-2014-0049 REJECTED

Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that triggers an invalid memory copy affecting certain cancel_work_item data.

EPSS 0.20% · 41.5th percentile

Risk Scores

EPSS Score
0.20%
41.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux-lts-utopic0
Ubuntu:16.04:LTSlinux-raspi20
Ubuntu:14.04:LTSlinux-lts-xenial0
Ubuntu:16.04:LTSlinux-gke0
Ubuntu:14.04:LTSlinux-aws0
Ubuntu:14.04:LTSlinux-lts-wily0
Ubuntu:16.04:LTSlinux-hwe0
Ubuntu:16.04:LTSlinux-snapdragon0
Ubuntu:14.04:LTSlinux3.12.0-4.12, 3.12.0-5.13, 3.12.0-7.15
Ubuntu:16.04:LTSlinux0
Ubuntu:14.04:LTSlinux-lts-vivid0
Ubuntu:16.04:LTSlinux-aws0

Timeline

References

Open in Interactive Console →