CVE-2014-0055: Medium severity redhat Enterprise Linux vulnerability
A flaw was found in the way getrxbufs() function handled error conditions reported by vhostgetvqdesc().
A privileged user in the guest could use this flaw to crash the host.
Other sources
The getrxbufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhostgetvqdesc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (RHEL 6) vhost-net subsystemto a version that resolves this vulnerability.Fixed in 2.6.32-431.11.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0055?
CVE-2014-0055 is considered a critical vulnerability as it allows a privileged user in the guest to crash the host.
How do I fix CVE-2014-0055?
To fix CVE-2014-0055, upgrade to the recommended versions of the Linux kernel, such as 5.10.223-1, 5.10.226-1, or other specified versions.
What software is affected by CVE-2014-0055?
CVE-2014-0055 affects Red Hat Enterprise Linux 6.0 and specific versions of the Linux kernel provided by Debian.
What causes the vulnerability in CVE-2014-0055?
CVE-2014-0055 is caused by a flaw in the get_rx_bufs() function's handling of error conditions in the vhost-net subsystem.
Is CVE-2014-0055 specific to certain Linux distributions?
Yes, CVE-2014-0055 specifically impacts Red Hat Enterprise Linux and certain versions of Debian's Linux kernel.