Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2014-3601

MEDIUM severity · CVSS 4.3 · CWE-189
4.3CVSS MEDIUM

Summary

The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.

Impact & exploitability

Attack vectorAdjacent
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)1%

AV:A/AC:H/Au:S/C:N/I:N/A:C

Affected products we track (2)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.