SB2013032201 - Input validation error in Linux kernel
Published: March 22, 2013 Updated: June 1, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2013-1798)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.
Remediation
Install update from vendor's website.
References
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.103
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.19
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.3
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.214
- https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.171
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6