First published: Tue Sep 12 2017(Updated: )
A reachable assertion failure flaw was found in the Linux kernel built with KVM virtualisation(CONFIG_KVM) support with Virtual Function I/O feature (CONFIG_VFIO) enabled. This failure could occur if a malicious guest device sent a virtual interrupt (guest IRQ) with a larger (>1024) index value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-862.rt56.804.el7 | 0:3.10.0-862.rt56.804.el7 |
redhat/kernel | <0:3.10.0-862.el7 | 0:3.10.0-862.el7 |
redhat/kernel | <0:3.10.0-693.25.2.el7 | 0:3.10.0-693.25.2.el7 |
redhat/kernel | <3.10.0-720.el7 | 3.10.0-720.el7 |
Linux Kernel | <=4.13.3 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.135-1 6.12.22-1 6.12.25-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2017-1000252 has a severity level of medium due to the potential for exploitation by a malicious guest device.
To fix CVE-2017-1000252, upgrade your kernel to one of the patched versions specifically mentioned in the advisory.
CVE-2017-1000252 affects Linux kernel versions prior to 4.13.3 that are built with KVM virtualization and VFIO enabled.
Yes, CVE-2017-1000252 can result in a denial of service condition due to an assertion failure.
Configurations that have KVM virtualization and Virtual Function I/O (VFIO) feature enabled are susceptible to CVE-2017-1000252.