Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5164

Опубликовано: 30 мар. 2026
Источник: nvd
CVSS3: 6.7
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in virtio-win. The RhelDoUnMap() function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:virtio-win:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00112
Низкий

6.7 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 6.7
redhat
4 месяца назад

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS).

CVSS3: 6.7
github
4 месяца назад

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial of Service (DoS).

EPSS

Процентиль: 2%
0.00112
Низкий

6.7 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-120