oss-sec mailing list archives

CVE-2020-27152 Kernel: KVM: host stack overflow via loop due to lazy update IOAPIC


From: P J P <ppandit () redhat com>
Date: Tue, 3 Nov 2020 16:25:31 +0530 (IST)

  Hello,

A stack overflow via an infinite loop condition issue was found in the KVM hypervisor of the Linux kernel. It could occur while processing interrupts because irq state is erroneously set. A guest user may use this flaw to crash the host kernel resulting in DoS scenario.

Upstream patch:
---------------
  -> https://git.kernel.org/linus/77377064c3a94911339f13ce113b3abf265e06da

'CVE-2020-27152' assigned via -> https://cveform.mitre.org/

Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
8685 545E B54C 486B C6EB 271E E285 8B5A F050 DE8D


Current thread: