First published: Mon Feb 05 2018(Updated: )
Improper validation in the bnx2x network card driver of the Linux kernel version 4.15 can allow for denial of service (DoS) attacks via a packet with a gso_size larger than ~9700 bytes. Untrusted guest VMs can exploit this vulnerability in the host machine, causing a crash in the network card. References: <a href="https://patchwork.ozlabs.org/patch/859410/">https://patchwork.ozlabs.org/patch/859410/</a> <a href="https://marc.info/?t=151606867000005&r=1&w=2">https://marc.info/?t=151606867000005&r=1&w=2</a> <a href="http://lists.openwall.net/netdev/2018/01/16/40">http://lists.openwall.net/netdev/2018/01/16/40</a> <a href="http://lists.openwall.net/netdev/2018/01/18/96">http://lists.openwall.net/netdev/2018/01/18/96</a> Upstream commits: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8914a595110a6eca69a5e275b323f5d09e18f4f9">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8914a595110a6eca69a5e275b323f5d09e18f4f9</a> <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2b16f048729bf35e6c28a40cbfad07239f9dcd90">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=2b16f048729bf35e6c28a40cbfad07239f9dcd90</a>
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=2.6.12<4.4.181 | |
Linux Linux kernel | >=4.5.0<4.9.159 | |
Linux Linux kernel | >=4.10<4.14.102 | |
Linux Linux kernel | >=4.15<4.16 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Debian Debian Linux | =8.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.