1
PublicDateAtUSN: 2014-10-23
2
Candidate: CVE-2014-3646
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3646
6
https://usn.ubuntu.com/usn/usn-2394-1
7
https://usn.ubuntu.com/usn/usn-2395-1
8
https://usn.ubuntu.com/usn/usn-2396-1
9
https://usn.ubuntu.com/usn/usn-2417-1
10
https://usn.ubuntu.com/usn/usn-2418-1
12
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2
13
does not have an exit handler for the INVVPID instruction, which allows
14
guest OS users to cause a denial of service (guest OS crash) via a crafted
17
A local unprivileged guest user could use this flaw to crash the
20
A flaw was discovered with the handling of the invept instruction in the
21
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
22
guest user could exploit this flaw to cause a denial of service (system
25
jdstrand> android kernels (flo, goldfish, grouper, maguro, mako and manta) are
26
not supported on the Ubuntu Touch 14.04 preview kernels
27
jdstrand> linux-lts-saucy no longer receives official support
28
jdstrand> linux-lts-quantal no longer receives official support
29
jdstrand> CVE disclosure was part of miscoordinated CRD (various (incomplete)
30
commits were publicly leaked by other vendors and upstream before the embargo
32
jdstrand> Updates for linux on Ubuntu 14.04 LTS were made available to users
33
on 2014/10/28 but due to a process error, USN publication did not happen
35
jdstrand> Updates for linux-lts-trusty on Ubuntu 12.04 LTS were made available
36
to users on 2014/10/29 but due to a process error, USN publication did not
37
happen until 2014/10/30.
38
jdstrand> Updates for linux on Ubuntu 14.10 were made available to users on
39
2014/10/28 but due to a process error, USN publication did not happen until
42
https://launchpad.net/bugs/1384544
44
Discovered-by: Reported by Advanced Threat Research team at Intel Security.
48
break-fix: - a642fc305053cc1c6e47e4f4df327895747ab485
49
upstream_linux: released (3.18~rc2)
50
lucid_linux: ignored (reached end-of-life)
51
precise_linux: released (3.2.0-72.107)
52
precise/esm_linux: released (3.2.0-72.107)
53
trusty_linux: released (3.13.0-39.66)
54
utopic_linux: released (3.16.0-24.32)
55
vivid_linux: not-affected (3.16.0-24.32)
56
vivid/ubuntu-core_linux: not-affected (3.16.0-24.32)
57
vivid/stable-phone-overlay_linux: DNE
58
wily_linux: not-affected (3.19.0-15.15)
59
xenial_linux: not-affected (4.2.0-16.19)
60
yakkety_linux: not-affected (4.4.0-21.37)
61
zesty_linux: not-affected (4.8.0-22.24)
62
devel_linux: not-affected (4.10.0-19.21)
65
upstream_linux-ec2: released (3.18~rc2)
66
lucid_linux-ec2: ignored (reached end-of-life)
67
precise_linux-ec2: DNE
68
precise/esm_linux-ec2: DNE
72
vivid/ubuntu-core_linux-ec2: DNE
73
vivid/stable-phone-overlay_linux-ec2: DNE
76
yakkety_linux-ec2: DNE
80
Patches_linux-mvl-dove:
81
upstream_linux-mvl-dove: released (3.18~rc2)
82
lucid_linux-mvl-dove: ignored (reached end-of-life)
83
precise_linux-mvl-dove: DNE
84
precise/esm_linux-mvl-dove: DNE
85
trusty_linux-mvl-dove: DNE
86
utopic_linux-mvl-dove: DNE
87
vivid_linux-mvl-dove: DNE
88
vivid/ubuntu-core_linux-mvl-dove: DNE
89
vivid/stable-phone-overlay_linux-mvl-dove: DNE
90
wily_linux-mvl-dove: DNE
91
xenial_linux-mvl-dove: DNE
92
yakkety_linux-mvl-dove: DNE
93
zesty_linux-mvl-dove: DNE
94
devel_linux-mvl-dove: DNE
96
Patches_linux-ti-omap4:
97
upstream_linux-ti-omap4: released (3.18~rc2)
98
lucid_linux-ti-omap4: DNE
99
precise_linux-ti-omap4: released (3.2.0-1456.76)
100
precise/esm_linux-ti-omap4: DNE (precise was released [3.2.0-1456.76])
101
trusty_linux-ti-omap4: DNE
102
utopic_linux-ti-omap4: DNE
103
vivid_linux-ti-omap4: DNE
104
vivid/ubuntu-core_linux-ti-omap4: DNE
105
vivid/stable-phone-overlay_linux-ti-omap4: DNE
106
wily_linux-ti-omap4: DNE
107
xenial_linux-ti-omap4: DNE
108
yakkety_linux-ti-omap4: DNE
109
zesty_linux-ti-omap4: DNE
110
devel_linux-ti-omap4: DNE
112
Patches_linux-fsl-imx51:
113
upstream_linux-fsl-imx51: released (3.18~rc2)
114
lucid_linux-fsl-imx51: ignored (reached end-of-life, does not affect buildd)
115
precise_linux-fsl-imx51: DNE
116
precise/esm_linux-fsl-imx51: DNE
117
trusty_linux-fsl-imx51: DNE
118
utopic_linux-fsl-imx51: DNE
119
vivid_linux-fsl-imx51: DNE
120
vivid/ubuntu-core_linux-fsl-imx51: DNE
121
vivid/stable-phone-overlay_linux-fsl-imx51: DNE
122
wily_linux-fsl-imx51: DNE
123
xenial_linux-fsl-imx51: DNE
124
yakkety_linux-fsl-imx51: DNE
125
zesty_linux-fsl-imx51: DNE
126
devel_linux-fsl-imx51: DNE
128
Patches_linux-linaro-omap:
129
upstream_linux-linaro-omap: released (3.18~rc2)
130
lucid_linux-linaro-omap: DNE
131
precise_linux-linaro-omap: ignored (abandoned)
132
precise/esm_linux-linaro-omap: DNE (precise was ignored [abandoned])
133
trusty_linux-linaro-omap: DNE
134
utopic_linux-linaro-omap: DNE
135
vivid_linux-linaro-omap: DNE
136
vivid/ubuntu-core_linux-linaro-omap: DNE
137
vivid/stable-phone-overlay_linux-linaro-omap: DNE
138
wily_linux-linaro-omap: DNE
139
xenial_linux-linaro-omap: DNE
140
yakkety_linux-linaro-omap: DNE
141
zesty_linux-linaro-omap: DNE
142
devel_linux-linaro-omap: DNE
144
Patches_linux-linaro-shared:
145
upstream_linux-linaro-shared: released (3.18~rc2)
146
lucid_linux-linaro-shared: DNE
147
precise_linux-linaro-shared: ignored (abandoned)
148
precise/esm_linux-linaro-shared: DNE (precise was ignored [abandoned])
149
trusty_linux-linaro-shared: DNE
150
utopic_linux-linaro-shared: DNE
151
vivid_linux-linaro-shared: DNE
152
vivid/ubuntu-core_linux-linaro-shared: DNE
153
vivid/stable-phone-overlay_linux-linaro-shared: DNE
154
wily_linux-linaro-shared: DNE
155
xenial_linux-linaro-shared: DNE
156
yakkety_linux-linaro-shared: DNE
157
zesty_linux-linaro-shared: DNE
158
devel_linux-linaro-shared: DNE
160
Patches_linux-linaro-vexpress:
161
upstream_linux-linaro-vexpress: released (3.18~rc2)
162
lucid_linux-linaro-vexpress: DNE
163
precise_linux-linaro-vexpress: ignored (abandoned)
164
precise/esm_linux-linaro-vexpress: DNE (precise was ignored [abandoned])
165
trusty_linux-linaro-vexpress: DNE
166
utopic_linux-linaro-vexpress: DNE
167
vivid_linux-linaro-vexpress: DNE
168
vivid/ubuntu-core_linux-linaro-vexpress: DNE
169
vivid/stable-phone-overlay_linux-linaro-vexpress: DNE
170
wily_linux-linaro-vexpress: DNE
171
xenial_linux-linaro-vexpress: DNE
172
yakkety_linux-linaro-vexpress: DNE
173
zesty_linux-linaro-vexpress: DNE
174
devel_linux-linaro-vexpress: DNE
176
Patches_linux-qcm-msm:
177
upstream_linux-qcm-msm: released (3.18~rc2)
178
lucid_linux-qcm-msm: ignored (abandoned)
179
precise_linux-qcm-msm: ignored (abandoned)
180
precise/esm_linux-qcm-msm: DNE (precise was ignored [abandoned])
181
trusty_linux-qcm-msm: DNE
182
utopic_linux-qcm-msm: DNE
183
vivid_linux-qcm-msm: DNE
184
vivid/ubuntu-core_linux-qcm-msm: DNE
185
vivid/stable-phone-overlay_linux-qcm-msm: DNE
186
wily_linux-qcm-msm: DNE
187
xenial_linux-qcm-msm: DNE
188
yakkety_linux-qcm-msm: DNE
189
zesty_linux-qcm-msm: DNE
190
devel_linux-qcm-msm: DNE
192
Tags_linux-armadaxp: not-ue
193
Patches_linux-armadaxp:
194
upstream_linux-armadaxp: released (3.18~rc2)
195
lucid_linux-armadaxp: DNE
196
precise_linux-armadaxp: released (3.2.0-1641.59)
197
precise/esm_linux-armadaxp: DNE (precise was released [3.2.0-1641.59])
198
trusty_linux-armadaxp: DNE
199
utopic_linux-armadaxp: DNE
200
vivid_linux-armadaxp: DNE
201
vivid/ubuntu-core_linux-armadaxp: DNE
202
vivid/stable-phone-overlay_linux-armadaxp: DNE
203
wily_linux-armadaxp: DNE
204
xenial_linux-armadaxp: DNE
205
yakkety_linux-armadaxp: DNE
206
zesty_linux-armadaxp: DNE
207
devel_linux-armadaxp: DNE
209
Tags_linux-lts-quantal: not-ue
210
Patches_linux-lts-quantal: DNE
211
upstream_linux-lts-quantal: released (3.18~rc2)
212
lucid_linux-lts-quantal: DNE
213
precise_linux-lts-quantal: ignored (was pending [3.5.0-57.84~precise1] OEM release)
214
precise/esm_linux-lts-quantal: DNE (precise was ignored [was pending [3.5.0-57.84~precise1] OEM release])
215
trusty_linux-lts-quantal: DNE
216
utopic_linux-lts-quantal: DNE
217
vivid_linux-lts-quantal: DNE
218
vivid/ubuntu-core_linux-lts-quantal: DNE
219
vivid/stable-phone-overlay_linux-lts-quantal: DNE
220
wily_linux-lts-quantal: DNE
221
xenial_linux-lts-quantal: DNE
222
yakkety_linux-lts-quantal: DNE
223
zesty_linux-lts-quantal: DNE
224
devel_linux-lts-quantal: DNE
226
Patches_linux-lts-raring:
227
upstream_linux-lts-raring: released (3.18~rc2)
228
lucid_linux-lts-raring: DNE
229
precise_linux-lts-raring: ignored (was needs-triage now end-of-life)
230
precise/esm_linux-lts-raring: DNE (precise was ignored [was needs-triage now end-of-life])
231
trusty_linux-lts-raring: DNE
232
utopic_linux-lts-raring: DNE
233
vivid_linux-lts-raring: DNE
234
vivid/ubuntu-core_linux-lts-raring: DNE
235
vivid/stable-phone-overlay_linux-lts-raring: DNE
236
wily_linux-lts-raring: DNE
237
xenial_linux-lts-raring: DNE
238
yakkety_linux-lts-raring: DNE
239
zesty_linux-lts-raring: DNE
240
devel_linux-lts-raring: DNE
242
Tags_linux-lts-saucy: not-ue
243
Patches_linux-lts-saucy:
244
upstream_linux-lts-saucy: released (3.18~rc2)
245
lucid_linux-lts-saucy: DNE
246
precise_linux-lts-saucy: ignored (was pending [3.11.0-30.51~precise1] OEM release)
247
precise/esm_linux-lts-saucy: DNE (precise was ignored [was pending [3.11.0-30.51~precise1] OEM release])
248
trusty_linux-lts-saucy: DNE
249
utopic_linux-lts-saucy: DNE
250
vivid_linux-lts-saucy: DNE
251
vivid/ubuntu-core_linux-lts-saucy: DNE
252
vivid/stable-phone-overlay_linux-lts-saucy: DNE
253
wily_linux-lts-saucy: DNE
254
xenial_linux-lts-saucy: DNE
255
yakkety_linux-lts-saucy: DNE
256
zesty_linux-lts-saucy: DNE
257
devel_linux-lts-saucy: DNE
259
Patches_linux-lts-trusty:
260
upstream_linux-lts-trusty: released (3.18~rc2)
261
lucid_linux-lts-trusty: DNE
262
precise_linux-lts-trusty: released (3.13.0-39.66~precise1)
263
precise/esm_linux-lts-trusty: released (3.13.0-39.66~precise1)
264
trusty_linux-lts-trusty: DNE
265
utopic_linux-lts-trusty: DNE
266
vivid_linux-lts-trusty: DNE
267
vivid/ubuntu-core_linux-lts-trusty: DNE
268
vivid/stable-phone-overlay_linux-lts-trusty: DNE
269
wily_linux-lts-trusty: DNE
270
xenial_linux-lts-trusty: DNE
271
yakkety_linux-lts-trusty: DNE
272
zesty_linux-lts-trusty: DNE
273
devel_linux-lts-trusty: DNE
275
Patches_linux-goldfish:
276
upstream_linux-goldfish: released (3.18~rc2)
277
lucid_linux-goldfish: DNE
278
precise_linux-goldfish: DNE
279
precise/esm_linux-goldfish: DNE
280
trusty_linux-goldfish: ignored
281
utopic_linux-goldfish: ignored (reached end-of-life)
282
vivid_linux-goldfish: ignored (reached end-of-life)
283
vivid/ubuntu-core_linux-goldfish: DNE
284
vivid/stable-phone-overlay_linux-goldfish: DNE
285
wily_linux-goldfish: ignored (reached end-of-life)
286
xenial_linux-goldfish: ignored (abandoned)
287
yakkety_linux-goldfish: ignored (abandoned)
288
zesty_linux-goldfish: ignored (abandoned)
289
devel_linux-goldfish: DNE
291
Patches_linux-grouper:
292
upstream_linux-grouper: released (3.18~rc2)
293
lucid_linux-grouper: DNE
294
precise_linux-grouper: DNE
295
precise/esm_linux-grouper: DNE
296
trusty_linux-grouper: ignored
297
utopic_linux-grouper: ignored (reached end-of-life)
298
vivid_linux-grouper: DNE
299
vivid/ubuntu-core_linux-grouper: DNE
300
vivid/stable-phone-overlay_linux-grouper: DNE
301
wily_linux-grouper: DNE
302
xenial_linux-grouper: DNE
303
yakkety_linux-grouper: DNE
304
zesty_linux-grouper: DNE
305
devel_linux-grouper: DNE
307
Patches_linux-maguro:
308
upstream_linux-maguro: released (3.18~rc2)
309
lucid_linux-maguro: DNE
310
precise_linux-maguro: DNE
311
precise/esm_linux-maguro: DNE
312
trusty_linux-maguro: ignored
313
utopic_linux-maguro: DNE
314
vivid_linux-maguro: DNE
315
vivid/ubuntu-core_linux-maguro: DNE
316
vivid/stable-phone-overlay_linux-maguro: DNE
317
wily_linux-maguro: DNE
318
xenial_linux-maguro: DNE
319
yakkety_linux-maguro: DNE
320
zesty_linux-maguro: DNE
321
devel_linux-maguro: DNE
324
upstream_linux-mako: released (3.18~rc2)
325
lucid_linux-mako: DNE
326
precise_linux-mako: DNE
327
precise/esm_linux-mako: DNE
328
trusty_linux-mako: ignored
329
utopic_linux-mako: ignored (reached end-of-life)
330
vivid_linux-mako: ignored (reached end-of-life)
331
vivid/ubuntu-core_linux-mako: DNE
332
vivid/stable-phone-overlay_linux-mako: ignored (abandoned)
333
wily_linux-mako: ignored (reached end-of-life)
334
xenial_linux-mako: ignored (abandoned)
335
yakkety_linux-mako: ignored (abandoned)
336
zesty_linux-mako: DNE
337
devel_linux-mako: DNE
340
upstream_linux-manta: released (3.18~rc2)
341
lucid_linux-manta: DNE
342
precise_linux-manta: DNE
343
precise/esm_linux-manta: DNE
344
trusty_linux-manta: ignored
345
utopic_linux-manta: ignored (reached end-of-life)
346
vivid_linux-manta: ignored (reached end-of-life)
347
vivid/ubuntu-core_linux-manta: DNE
348
vivid/stable-phone-overlay_linux-manta: DNE
349
wily_linux-manta: ignored (reached end-of-life)
350
xenial_linux-manta: DNE
351
yakkety_linux-manta: DNE
352
zesty_linux-manta: DNE
353
devel_linux-manta: DNE
356
upstream_linux-flo: released (3.18~rc2)
358
precise_linux-flo: DNE
359
precise/esm_linux-flo: DNE
360
trusty_linux-flo: ignored
361
utopic_linux-flo: ignored (reached end-of-life)
362
vivid_linux-flo: ignored (reached end-of-life)
363
vivid/ubuntu-core_linux-flo: DNE
364
vivid/stable-phone-overlay_linux-flo: ignored (abandoned)
365
wily_linux-flo: ignored (reached end-of-life)
366
xenial_linux-flo: ignored (abandoned)
367
yakkety_linux-flo: ignored (abandoned)
371
Patches_linux-lts-utopic:
372
upstream_linux-lts-utopic: released (3.18~rc2)
373
lucid_linux-lts-utopic: DNE
374
precise_linux-lts-utopic: DNE
375
precise/esm_linux-lts-utopic: DNE
376
trusty_linux-lts-utopic: not-affected (3.16.0-25.33~14.04.2)
377
utopic_linux-lts-utopic: DNE
378
vivid_linux-lts-utopic: DNE
379
vivid/ubuntu-core_linux-lts-utopic: DNE
380
vivid/stable-phone-overlay_linux-lts-utopic: DNE
381
wily_linux-lts-utopic: DNE
382
xenial_linux-lts-utopic: DNE
383
yakkety_linux-lts-utopic: DNE
384
zesty_linux-lts-utopic: DNE
385
devel_linux-lts-utopic: DNE
387
Patches_linux-lts-vivid:
388
upstream_linux-lts-vivid: released (3.18~rc2)
389
lucid_linux-lts-vivid: DNE
390
precise_linux-lts-vivid: DNE
391
precise/esm_linux-lts-vivid: DNE
392
trusty_linux-lts-vivid: not-affected (3.19.0-18.18~14.04.1)
393
utopic_linux-lts-vivid: DNE
394
vivid_linux-lts-vivid: DNE
395
vivid/ubuntu-core_linux-lts-vivid: DNE
396
vivid/stable-phone-overlay_linux-lts-vivid: DNE
397
wily_linux-lts-vivid: DNE
398
xenial_linux-lts-vivid: DNE
399
yakkety_linux-lts-vivid: DNE
400
zesty_linux-lts-vivid: DNE
401
devel_linux-lts-vivid: DNE
403
Patches_linux-krillin:
404
product_linux-krillin: ignored (was needed now end-of-life)
406
Patches_linux-vegetahd:
407
product_linux-vegetahd: ignored (was needed now end-of-life)
409
Patches_linux-lts-wily:
410
upstream_linux-lts-wily: released (3.18~rc2)
411
precise_linux-lts-wily: DNE
412
precise/esm_linux-lts-wily: DNE
413
trusty_linux-lts-wily: not-affected (4.2.0-18.22~14.04.1)
414
vivid_linux-lts-wily: DNE
415
vivid/ubuntu-core_linux-lts-wily: DNE
416
vivid/stable-phone-overlay_linux-lts-wily: DNE
417
wily_linux-lts-wily: DNE
418
xenial_linux-lts-wily: DNE
419
yakkety_linux-lts-wily: DNE
420
zesty_linux-lts-wily: DNE
421
devel_linux-lts-wily: DNE
423
Patches_linux-raspi2:
424
upstream_linux-raspi2: released (3.18~rc2)
425
precise_linux-raspi2: DNE
426
precise/esm_linux-raspi2: DNE
427
trusty_linux-raspi2: DNE
428
vivid_linux-raspi2: DNE
429
vivid/ubuntu-core_linux-raspi2: released (4.2.0-1014.21)
430
vivid/stable-phone-overlay_linux-raspi2: DNE
431
wily_linux-raspi2: not-affected (4.2.0-1008.12)
432
xenial_linux-raspi2: not-affected (4.2.0-1013.19)
433
yakkety_linux-raspi2: not-affected (4.4.0-1009.10)
434
zesty_linux-raspi2: not-affected (4.8.0-1013.15)
435
devel_linux-raspi2: not-affected (4.10.0-1004.6)
437
Patches_linux-lts-xenial:
438
upstream_linux-lts-xenial: released (3.18~rc2)
439
precise_linux-lts-xenial: DNE
440
precise/esm_linux-lts-xenial: DNE
441
trusty_linux-lts-xenial: not-affected (4.4.0-13.29~14.04.1)
442
vivid_linux-lts-xenial: DNE
443
vivid/ubuntu-core_linux-lts-xenial: DNE
444
vivid/stable-phone-overlay_linux-lts-xenial: DNE
445
wily_linux-lts-xenial: DNE
446
xenial_linux-lts-xenial: DNE
447
yakkety_linux-lts-xenial: DNE
448
zesty_linux-lts-xenial: DNE
449
devel_linux-lts-xenial: DNE
451
Patches_linux-snapdragon:
452
upstream_linux-snapdragon: released (3.18~rc2)
453
precise_linux-snapdragon: DNE
454
precise/esm_linux-snapdragon: DNE
455
trusty_linux-snapdragon: DNE
456
vivid/ubuntu-core_linux-snapdragon: DNE
457
vivid/stable-phone-overlay_linux-snapdragon: DNE
458
wily_linux-snapdragon: DNE
459
xenial_linux-snapdragon: not-affected (4.4.0-1012.12)
460
yakkety_linux-snapdragon: not-affected (4.4.0-1012.12)
461
zesty_linux-snapdragon: not-affected (4.4.0-1029.32)
462
devel_linux-snapdragon: not-affected (4.4.0-1050.54)
465
upstream_linux-aws: released (3.18~rc2)
466
precise_linux-aws: DNE
467
precise/esm_linux-aws: DNE
468
trusty_linux-aws: not-affected (4.4.0-1002.2)
469
vivid/ubuntu-core_linux-aws: DNE
470
vivid/stable-phone-overlay_linux-aws: DNE
471
xenial_linux-aws: not-affected (4.4.0-1001.10)
472
yakkety_linux-aws: DNE
476
Patches_linux-hwe-edge:
477
upstream_linux-hwe-edge: released (3.18~rc2)
478
precise_linux-hwe-edge: DNE
479
precise/esm_linux-hwe-edge: DNE
480
trusty_linux-hwe-edge: DNE
481
vivid/ubuntu-core_linux-hwe-edge: DNE
482
vivid/stable-phone-overlay_linux-hwe-edge: DNE
483
xenial_linux-hwe-edge: not-affected (4.8.0-28.30~16.04.1)
484
yakkety_linux-hwe-edge: DNE
485
zesty_linux-hwe-edge: DNE
486
devel_linux-hwe-edge: DNE
489
upstream_linux-hwe: released (3.18~rc2)
490
precise_linux-hwe: DNE
491
precise/esm_linux-hwe: DNE
492
trusty_linux-hwe: DNE
493
vivid/ubuntu-core_linux-hwe: DNE
494
vivid/stable-phone-overlay_linux-hwe: DNE
495
xenial_linux-hwe: not-affected (4.8.0-36.36~16.04.1)
496
yakkety_linux-hwe: DNE
501
upstream_linux-gke: released (3.18~rc2)
502
precise_linux-gke: DNE
503
precise/esm_linux-gke: DNE
504
trusty_linux-gke: DNE
505
vivid/ubuntu-core_linux-gke: DNE
506
vivid/stable-phone-overlay_linux-gke: DNE
507
xenial_linux-gke: not-affected (4.4.0-1003.3)
508
yakkety_linux-gke: DNE