virtio-net: Add validation for used length
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.4epss 0.3%
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: Add validation for used length
This adds validation for used length (might come
from an untrusted device) to avoid data corruption
or loss.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/3133e01514c3c498f2b01ff210ee6134b70c663chttps://git.kernel.org/stable/c/ad993a95c508417acdeb15244109e009e50d8758https://git.kernel.org/stable/c/ba710baa1cc1b17a0483f7befe03e696efd17292https://git.kernel.org/stable/c/c1b40d1959517ff2ea473d40eeab4691d6d62462https://git.kernel.org/stable/c/c92298d228f61589dd21657af2bea95fc866b813