ALAS-2020-1338 --- kernel perfID: oval:org.secpod.oval:def:1601094 | Date: (C)2020-02-11 (M)2024-05-04 |
Class: PATCH | Family: unix |
A memory leak in the crypto_report function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service by triggering crypto_report_alg failures, aka CID-ffdde5932042. An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel"s KVM hypervisor handled the "KVM_GET_EMULATED_CPUID" ioctl request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the "/dev/kvm" device could use this flaw to crash the system, resulting in a denial of service
Platform: |
Amazon Linux AMI |