CVE-2014-8159: Canonical Ubuntu Linux
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only; version 14.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Linux Linux Kernel: from 2.6.12, before 3.2.69 (fixed in 3.2.69); from 3.3, before 3.4.108 (fixed in 3.4.108); from 3.5, before 3.10.75 (fixed in 3.10.75); from 3.11, before 3.12.41 (fixed in 3.12.41); from 3.13, before 3.14.39 (fixed in 3.14.39); from 3.15, before 3.16.35 (fixed in 3.16.35); …
Published 2015-03-16. Last modified 2026-06-17.