CVE-2014-3646
MEDIUMLinux Kernel < 3.17.2 - Denial of Service
Title source: ruleDescription
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
References (12)
Scores
CVSS v3
5.5
EPSS
0.0010
EPSS Percentile
27.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
Status
draft
Affected Products (6)
linux/linux_kernel
< 3.17.2
redhat/enterprise_linux
canonical/ubuntu_linux
debian/debian_linux
opensuse/evergreen
suse/suse_linux_enterprise_server
Timeline
Published
Nov 10, 2014
Tracked Since
Feb 18, 2026