MGASA-2014-0475

Source
https://advisories.mageia.org/MGASA-2014-0475.html
Import Source
https://advisories.mageia.org/MGASA-2014-0475.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0475
Related
Published
2014-11-21T12:44:16Z
Modified
2014-11-21T12:21:42Z
Summary
Updated kernel packages fix security vulnerabilities
Details

This kernel update is based on upstream -longterm 3.10.60 and fixes the following security issues:

The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non- canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsrinterception function in arch/x86/kvm/svm.c and the handlewrmsr function in arch/x86/kvm/vmx.c (CVE-2014-3610).

Race condition in the _kvmmigratepittimer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation (CVE-2014-3611).

arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application (CVE-2014-3647).

For other upstream changes, read the referenced changelogs.

References
Credits

Affected packages

Mageia:3 / kmod-broadcom-wl

Package

Name
kmod-broadcom-wl
Purl
pkg:rpm/mageia/kmod-broadcom-wl?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.30.223.141-25.mga3.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Mageia:3 / kmod-fglrx

Package

Name
kmod-fglrx
Purl
pkg:rpm/mageia/kmod-fglrx?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.251-15.mga3.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Mageia:3 / kmod-nvidia173

Package

Name
kmod-nvidia173
Purl
pkg:rpm/mageia/kmod-nvidia173?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
173.14.38-39.mga3.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Mageia:3 / kmod-nvidia304

Package

Name
kmod-nvidia304
Purl
pkg:rpm/mageia/kmod-nvidia304?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
304.108-25.mga3.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Mageia:3 / kmod-nvidia-current

Package

Name
kmod-nvidia-current
Purl
pkg:rpm/mageia/kmod-nvidia-current?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
319.60-25.mga3.nonfree

Ecosystem specific

{
    "section": "nonfree"
}

Mageia:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.60-1.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / kernel-userspace-headers

Package

Name
kernel-userspace-headers
Purl
pkg:rpm/mageia/kernel-userspace-headers?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.60-1.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / kmod-vboxadditions

Package

Name
kmod-vboxadditions
Purl
pkg:rpm/mageia/kmod-vboxadditions?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.18-3.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.18-3.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3-25.mga3

Ecosystem specific

{
    "section": "core"
}