Quantcast
Channel: Mellanox Interconnect Community: Message List
Viewing all articles
Browse latest Browse all 6226

CVE 2014-8159 vulnerability

$
0
0

Redhat released yesterday a new kernel and seems that there is local root hole in (u)verbs implementation. Has anyone figured out is MLNX OFED affected as well?

 

It was found that the Linux kernel's Infiniband subsystem did not

properly sanitize input parameters while registering memory regions from

user space via the (u)verbs API. A local user with access to a

/dev/infiniband/uverbsX device could use this flaw to crash the system or,

potentially, escalate their privileges on the system. (CVE-2014-8159,

Important)


Viewing all articles
Browse latest Browse all 6226

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>