Linux Kernel is prone to an overflow condition. The setup_routing_entry() function in the KVM Subsystem fails to properly sanitize user-supplied input resulting in a buffer overflow. When handling Message Signaled Interrupts (MSI) routing entries, a local attacker can potentially cause a denial of service or execute arbitrary code.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Third-Party Solution
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
It has been reported that this issue has been fixed. Upgrade to version 3.0.72, or higher, to address this vulnerability.