UBUNTU-CVE-2014-0055
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-0055
UBUNTU-CVE-2014-0055
Summary:
Details: The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors.
References: https://ubuntu.com/security/CVE-2014-0055, https://bugzilla.redhat.com/show_bug.cgi?id=1062577, https://ubuntu.com/security/notices/USN-2223-1, https://ubuntu.com/security/notices/USN-2224-1, https://ubuntu.com/security/notices/USN-2225-1, https://ubuntu.com/security/notices/USN-2228-1, https://ubuntu.com/security/notices/USN-2235-1, https://ubuntu.com/security/notices/USN-2236-1, https://www.cve.org/CVERecord?id=CVE-2014-0055
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
