Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade linux-grsec | Sep 20, 2017 | Jul 29, 2013 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Jul 29, 2013 |
| Ubuntu | — | Upgrade linux-image-3.8.0-29-generic | Nov 8, 2024 | Jul 29, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub