Vulnerability in the vhost-net driver of the Linux kernel

In the vhost-net driver, which facilitates virtio net on the host environment side, tuvastatud haavatavus (CVE-2020-10942), which allows a local user to initiate a kernel stack overflow by sending a specially crafted ioctl(VHOST_NET_SET_BACKEND) to the /dev/vhost-net device. The issue is due to inadequate validation of the sk_family field in the get_raw_socket() function code.

Preliminary data suggests the vulnerability can be exploited to perform a local DoS attack by causing the kernel to crash (there is no information on the use of the triggered stack overflow for code execution).
Haavatavus on kõrvaldatud in the Linux kernel update 5.5.8. For distributions, updates can be monitored on the release pages for packages. Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch.

Allikas: opennet.ru

Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid 🔥 Osta usaldusväärne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster