In the vhost-net driver, which facilitates virtio net on the host environment side, haavatavus (), which allows a local user to initiate a kernel stack overflow by sending a specially crafted ioctl(VHOST_NET_SET_BACKEND) to the /dev/vhost-net device. The issue is due to inadequate validation of the sk_family field in the get_raw_socket() function code.
Preliminary data suggests the vulnerability can be exploited to perform a local DoS attack by causing the kernel to crash (there is no information on the use of the triggered stack overflow for code execution).
Haavatavus in the Linux kernel update 5.5.8. For distributions, updates can be monitored on the release pages for packages. , , , , , .
Allikas: opennet.ru
