Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 552748

Summary: Kernel: KVM SYSENTER emulation vulnerability (CVE-2015-0239)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: KernelAssignee: Gentoo Kernel Security <security-kernel>
Status: RESOLVED FIXED    
Severity: normal CC: kernel
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2015-06-21 13:52:30 UTC
CVE-2015-0239 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0239):
  The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel
  before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows
  guest OS users to gain guest OS privileges or cause a denial of service
  (guest OS crash) by triggering use of a 16-bit code segment for emulation of
  a SYSENTER instruction.