CVE-2015-5307
Published: 10 November 2015
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
From the Ubuntu security team
Ben Serebrin discovered that the KVM hypervisor implementation in the Linux kernel did not properly catch Alignment Check exceptions. An attacker in a guest virtual machine could use this to cause a denial of service (system crash) in the host OS.
Priority
Status
Package | Release | Status |
---|---|---|
linux Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-armadaxp Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-aws Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-ec2 Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-flo Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-fsl-imx51 Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-gke Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-goldfish Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-grouper Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-hwe Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-linaro-omap Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-linaro-shared Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-linaro-vexpress Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-quantal Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-raring Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-saucy Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-trusty Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-utopic Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-vivid Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-wily Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-maguro Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-mako Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-manta Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-mvl-dove Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-qcm-msm Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-raspi2 Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-snapdragon Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
linux-ti-omap4 Launchpad, Ubuntu, Debian |
upstream |
Released
(4.4~rc1)
|
virtualbox Launchpad, Ubuntu, Debian |
upstream |
Released
(5.0.14-dfsg-1)
|
xen Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
Notes
Author | Note |
---|---|
jdstrand | android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.10 and earlier preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support |
sbeattie | affects x86 kernels only fixed in upstream 54a20552e1eae07aa240fa370a0293e006b5faed ; however, it hadn't made it to linus' tree before we published kernels for it, so manually recording everything. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5307
- https://ubuntu.com/security/notices/USN-2806-1
- https://ubuntu.com/security/notices/USN-2805-1
- https://ubuntu.com/security/notices/USN-2802-1
- https://ubuntu.com/security/notices/USN-2801-1
- https://ubuntu.com/security/notices/USN-2804-1
- https://ubuntu.com/security/notices/USN-2800-1
- https://ubuntu.com/security/notices/USN-2803-1
- https://ubuntu.com/security/notices/USN-2807-1
- NVD
- Launchpad
- Debian