VDB
CVE-2010-0741
CVE-2010-0741
PUBLISHED
Reported by redhat · Published April 12, 2010
The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Apr 12, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- 1023798 vdb-entryx_refsource_SECTRACK
- RHSA-2010:0476 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- ADV-2010-0760 vdb-entryx_refsource_VUPEN
- [qemu-devel] 20091029 Re: qemu-kvm-0.11 regression, crashes on older guests with virtio network mailing-listx_refsource_MLIST
- oval:org.mitre.oval:def:11143 vdb-entrysignaturex_refsource_OVAL
- x_refsource_CONFIRM
- [qemu-devel] 20091029 [PATCH] whitelist host virtio networking features [was Re: qemu-kvm-0.11 regression, crashes on older ...] mailing-listx_refsource_MLIST
- RHSA-2010:0271 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- [oss-security] 20100329 CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux virtio-net driver mailing-listx_refsource_MLIST
- x_refsource_CONFIRM