CVE-2014-8134: Canonical Ubuntu Linux
Low severity, CVSS 3.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
- Linux Linux Kernel: up to and including 3.18
- Opensuse Evergreen: version 11.4 only
- Opensuse Opensuse: version 13.1 only
- Oracle Linux: version 6 only
- Suse Suse Linux Enterprise Server: version 11 only
Published 2014-12-12. Last modified 2026-06-17.