Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7q5-cw8v-48xh

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

EPSS

Процентиль: 60%
0.00409
Низкий

7.7 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 7 лет назад

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

CVSS3: 5.8
redhat
больше 7 лет назад

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

CVSS3: 7.7
nvd
больше 7 лет назад

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

CVSS3: 7.7
debian
больше 7 лет назад

Linux Linux kernel version at least v4.8 onwards, probably well before ...

oracle-oval
больше 6 лет назад

ELSA-2019-4570: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 60%
0.00409
Низкий

7.7 High

CVSS3

Дефекты

CWE-20