In the vhost-net driver, which enables virtio net operation on the host environment, vulnerability (), which allows a local user to initiate a stack overflow in the kernel by sending a specially crafted ioctl (VHOST_NET_SET_BACKEND) to the device /dev/vhost-net. The issue is caused by a lack of proper validation of the sk_family field in the get_raw_socket() function code.
According to preliminary data, the vulnerability could be exploited for a local DoS attack by triggering a kernel crash (there is no information about the use of the stack overflow to achieve code execution).
The vulnerability in the Linux kernel update 5.5.8. For distributions, updates can be monitored on the package release pages , , , , , .
Source: opennet.ru
