Vulnerability Database

314,433

Total vulnerabilities in the database

CVE-2014-0155

The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which allows guest OS users to cause a denial of service (host OS crash) via a crafted entry in the redirection table of an I/O APIC. NOTE: the affected code was moved to the ioapic_service function before the vulnerability was announced.

  • Published: Apr 14, 2014
  • Updated: Nov 9, 2025
  • CVE: CVE-2014-0155
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.5
  • AV:A/AC:L/Au:S/C:N/I:N/A:C

CWEs: