CVE-2013-6368
Publication date 14 December 2013
Last updated 24 July 2024
Ubuntu priority
The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.
From the Ubuntu Security Team
Andrew Honig reported an error in the Linux Kernel's Kernel Virtual Machine (KVM) VAPIC synchronization operation. A local user could exploit this flaw to gain privileges or cause a denial of service (system crash).
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 14.04 LTS trusty |
Not affected
|
linux-armadaxp | 14.04 LTS trusty | Not in release |
linux-ec2 | 14.04 LTS trusty | Not in release |
linux-flo | 14.04 LTS trusty | Ignored end of life, was needed |
linux-fsl-imx51 | 14.04 LTS trusty | Not in release |
linux-goldfish | 14.04 LTS trusty | Ignored end of life, was needed |
linux-grouper | 14.04 LTS trusty | Not in release |
linux-linaro-omap | 14.04 LTS trusty | Not in release |
linux-linaro-shared | 14.04 LTS trusty | Not in release |
linux-linaro-vexpress | 14.04 LTS trusty | Not in release |
linux-lts-quantal | 14.04 LTS trusty | Not in release |
linux-lts-raring | 14.04 LTS trusty | Not in release |
linux-lts-saucy | 14.04 LTS trusty | Not in release |
linux-lts-trusty | 14.04 LTS trusty | Not in release |
linux-maguro | 14.04 LTS trusty | Not in release |
linux-mako | 14.04 LTS trusty | Ignored end of life, was needed |
linux-manta | 14.04 LTS trusty | Ignored end of life, was needed |
linux-mvl-dove | 14.04 LTS trusty | Not in release |
linux-qcm-msm | 14.04 LTS trusty | Not in release |
linux-ti-omap4 | 14.04 LTS trusty | Not in release |
Notes
jdstrand
per upstream, not guest triggerable because write must be done in firmware which is before the guest starts. Also only affects certain processors per kernel team, too intrusive to backport
References
Related Ubuntu Security Notices (USN)
- USN-2138-1
- Linux kernel vulnerabilities
- 7 March 2014
- USN-2136-1
- Linux kernel (Raring HWE) vulnerabilities
- 7 March 2014
- USN-2113-1
- Linux kernel (Saucy HWE) vulnerabilities
- 18 February 2014
- USN-2139-1
- Linux kernel (OMAP4) vulnerabilities
- 7 March 2014
- USN-2134-1
- Linux kernel (OMAP4) vulnerabilities
- 7 March 2014
- USN-2135-1
- Linux kernel (Quantal HWE) vulnerabilities
- 7 March 2014
- USN-2133-1
- Linux kernel vulnerabilities
- 7 March 2014
- USN-2141-1
- Linux kernel (OMAP4) vulnerabilities
- 7 March 2014
- USN-2117-1
- Linux kernel vulnerabilities
- 18 February 2014