drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (memory corruption) or have unspecified other impact, by leveraging access to a vfio PCI device file for a VFIO_DEVICE_SET_IRQS ioctl call, aka a "state machine confusion bug."
http://rhn.redhat.com/errata/RHSA-2017-0386.html
http://rhn.redhat.com/errata/RHSA-2017-0387.html
http://www.openwall.com/lists/oss-security/2016/10/26/11
http://www.securityfocus.com/bid/93929
https://bugzilla.redhat.com/show_bug.cgi?id=1389258
https://github.com/torvalds/linux/commit/05692d7005a364add85c6e25a6c4447ce08f913a
Source: MITRE
Published: 2016-11-28
Updated: 2018-01-05
Type: CWE-119
Base Score: 7.2
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 3.9
Severity: HIGH
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions up to 4.8.11 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
124971 | EulerOS Virtualization for ARM 64 3.0.1.0 : kernel (EulerOS-SA-2019-1518) | Nessus | Huawei Local Security Checks | high |
124819 | EulerOS Virtualization 3.0.1.0 : kernel (EulerOS-SA-2019-1496) | Nessus | Huawei Local Security Checks | critical |
121650 | Photon OS 1.0: Linux PHSA-2016-0012 | Nessus | PhotonOS Local Security Checks | critical |
111846 | Photon OS 1.0: Dnsmasq / Grub2 / Haproxy / Linux / Nginx / Vim / Wget / Zookeeper PHSA-2016-0012 (deprecated) | Nessus | PhotonOS Local Security Checks | critical |
103326 | Ubuntu 14.04 LTS : linux vulnerabilities (USN-3422-1) (BlueBorne) | Nessus | Ubuntu Local Security Checks | high |
102511 | Oracle Linux 7 : kernel (ELSA-2017-1842-1) (Stack Clash) | Nessus | Oracle Linux Local Security Checks | critical |
101929 | Ubuntu 16.04 LTS : linux-hwe vulnerabilities (USN-3361-1) | Nessus | Ubuntu Local Security Checks | critical |
101431 | Virtuozzo 7 : kernel / kernel-abi-whitelists / kernel-debug / etc (VZLSA-2017-0386) | Nessus | Virtuozzo Local Security Checks | high |
100665 | Ubuntu 14.04 LTS : linux-lts-xenial vulnerabilities (USN-3312-2) | Nessus | Ubuntu Local Security Checks | critical |
100664 | Ubuntu 16.04 LTS : linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities (USN-3312-1) | Nessus | Ubuntu Local Security Checks | critical |
97558 | CentOS 7 : kernel (CESA-2017:0386) | Nessus | CentOS Local Security Checks | high |
97516 | Scientific Linux Security Update : kernel on SL7.x x86_64 (20170302) | Nessus | Scientific Linux Local Security Checks | high |
97510 | RHEL 7 : kernel-rt (RHSA-2017:0387) | Nessus | Red Hat Local Security Checks | high |
97509 | RHEL 7 : kernel (RHSA-2017:0386) | Nessus | Red Hat Local Security Checks | high |
97506 | Oracle Linux 7 : kernel (ELSA-2017-0386) | Nessus | Oracle Linux Local Security Checks | high |
97205 | SUSE SLES12 Security Update : kernel (SUSE-SU-2017:0471-1) | Nessus | SuSE Local Security Checks | high |
97189 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:0464-1) | Nessus | SuSE Local Security Checks | high |
97079 | OracleVM 3.4 : Unbreakable / etc (OVMSA-2017-0039) | Nessus | OracleVM Local Security Checks | high |
97057 | Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2017-3514) | Nessus | Oracle Linux Local Security Checks | high |
96603 | SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2017:0181-1) | Nessus | SuSE Local Security Checks | high |
95702 | openSUSE Security Update : the Linux Kernel (openSUSE-2016-1428) | Nessus | SuSE Local Security Checks | critical |
95701 | openSUSE Security Update : the Linux Kernel (openSUSE-2016-1426) | Nessus | SuSE Local Security Checks | critical |
95609 | Amazon Linux AMI : kernel (ALAS-2016-772) | Nessus | Amazon Linux Local Security Checks | high |
95308 | Fedora 23 : kernel (2016-ee3a114958) | Nessus | Fedora Local Security Checks | high |
94617 | Fedora 24 : kernel (2016-96d276367e) | Nessus | Fedora Local Security Checks | high |