CVE-2014-3601: Canonical Ubuntu Linux
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
- Linux Linux Kernel: up to and including 3.16.1; version 3.16.0 only
- Opensuse Evergreen: version 11.4 only
- Suse Linux Enterprise Real Time Extension: version 11.0 only
- Suse Linux Enterprise Server: version 11 only
- Suse Suse Linux Enterprise Server: version 11 only
Published 2014-09-01. Last modified 2026-06-17.