** Changed in: linux (Ubuntu Trusty) Status: New => Invalid ** Description changed:
The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors. + + Break-Fix: 8dd014adfea6f173c1ef6378f7e5e7924866c923 + a39ee449f96a2cd44ce056d8a0a112211a9b1a1f -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1298117 Title: CVE-2014-0055 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1298117/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs