First published: Thu Dec 01 2016(Updated: )
The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM PowerKVM | =2.1 | |
IBM PowerKVM | =2.1.0.2 | |
IBM PowerKVM | =2.1.1.0 | |
IBM PowerKVM | =2.1.1.2 | |
IBM PowerKVM | =2.1.1.3 | |
IBM PowerKVM | =3.1 | |
IBM PowerKVM | =3.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3044 is classified as a denial of service vulnerability with a high severity impact on the host OS.
To address CVE-2016-3044, upgrade IBM PowerKVM to version 2.1.1.3 or 3.1.0.2 and later.
CVE-2016-3044 affects IBM PowerKVM versions 2.1, 3.1, and their specific sub-versions prior to the patched releases.
Exploiting CVE-2016-3044 allows a guest OS user to create an infinite loop on the host OS, leading to a system hang.
To prevent exploitation of CVE-2016-3044, apply the necessary software updates and monitor for unusual activity within the host system.