drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host OS crash) or possibly gain privileges on the host OS via crafted packets, related to the handle_rx and get_rx_bufs functions.
2014-04-14T23:55:07.530
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.5 (MEDIUM)
AV:A/AC:H/Au:S/C:P/I:P/A:C
2.5
8.5
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 3.13.10 | Yes |