First published: Thu Feb 05 2015(Updated: )
Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <=3.18.0 | |
Linux Linux kernel | >3.6<3.10.90 | |
Linux Linux kernel | >=3.11<3.12.44 | |
Linux Linux kernel | >=3.13<3.14.57 | |
Linux Linux kernel | >=3.15<3.16.35 | |
Linux Linux kernel | >=3.17<3.18.25 | |
Linux Linux kernel | >=3.19<4.0 | |
Linux Linux kernel | =3.6 | |
Linux Linux kernel | =3.6-rc2 | |
Linux Linux kernel | =3.6-rc3 | |
Linux Linux kernel | =3.6-rc4 | |
Linux Linux kernel | =3.6-rc5 | |
Linux Linux kernel | =3.6-rc6 | |
Linux Linux kernel | =3.6-rc7 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.