Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000407

Опубликовано: 01 дек. 2017
Источник: redhat
CVSS3: 6.1
CVSS2: 4.6
EPSS Низкий

Описание

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

Linux kernel Virtualization Module (CONFIG_KVM) for the Intel processor family (CONFIG_KVM_INTEL) is vulnerable to a DoS issue. It could occur if a guest was to flood the I/O port 0x80 with write requests. A guest user could use this flaw to crash the host kernel resulting in DoS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelWill not fix
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2018:067610.04.2018
Red Hat Enterprise Linux 7kernelFixedRHSA-2018:106210.04.2018
Red Hat Enterprise Linux 7.4 Extended Update SupportkernelFixedRHSA-2019:117014.05.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=1520328Kernel: KVM: DoS via write flood to I/O port 0x80

EPSS

Процентиль: 63%
0.00465
Низкий

6.1 Medium

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 7.4
nvd
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 7.4
debian
больше 7 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, ...

CVSS3: 7.4
github
около 3 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

oracle-oval
больше 7 лет назад

ELSA-2018-4017: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 63%
0.00465
Низкий

6.1 Medium

CVSS3

4.6 Medium

CVSS2