A vulnerability in the vhost-net driver within the Linux kernel

In the vhost-net driver, which enables virtio net operation on the host environment, identified vulnerability (CVE-2020-10942), which allows a local user to initiate a stack overflow in the kernel by sending a specially crafted ioctl (VHOST_NET_SET_BACKEND) to the device /dev/vhost-net. The issue is caused by a lack of proper validation of the sk_family field in the get_raw_socket() function code.

According to preliminary data, the vulnerability could be exploited for a local DoS attack by triggering a kernel crash (there is no information about the use of the stack overflow to achieve code execution).
The vulnerability has been closed in the Linux kernel update 5.5.8. For distributions, updates can be monitored on the package release pages Debian, Ubuntu, SUSE/openSUSE, Arch, Alpine, ALT.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster