CVE-2014-0055
The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors.
- Affected products
- Alt Linux, Centos, Linux Kernel, Red Hat, Suse Linux Enterprise, Suse
- Redhat Enterprise Linux
- = 6.0
- CVSS 2.0
- 5.5 MEDIUM
- EPSS
- 0.6% (47th percentile)
- NVD status
- Modified
- Published
- 2014-03-26
CVE-2014-0055 at NVD
1 known exploit for CVE-2014-0055
Proof-of-concept code and exploit modules indexed by Sploitus