Local Privilege Escalation Vulnerability in InfiniBand Implementation on Red Hat Enterprise Linux
CVE-2014-8159

Currently unrated

Key Information:

Vendor
Linux
Vendor
CVE Published:
16 March 2015

Summary

The InfiniBand implementation within the Linux kernel in Red Hat Enterprise Linux 6 versions prior to 2.6.32-504.12.2 allows local users to exploit improper restrictions on User Verbs for memory registration. This vulnerability could enable attackers to access arbitrary physical memory locations. Successful exploitation may lead to a denial of service via system crashes or the elevation of privileges by leveraging access to uverbs devices located at /dev/infiniband/.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.