Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hcc-hc53-34f7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on the same host.

In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on the same host.

EPSS

Процентиль: 56%
0.00334
Низкий

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on the same host.

EPSS

Процентиль: 56%
0.00334
Низкий

Дефекты

CWE-119