Back

HIGH

qemu: Improper handling of erroneous data provided by Linux virtio-net driver

Published Apr 12, 2010

Description

The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).

Affected products

Remediation

No remediation recorded yet.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 12, 2010
Updated Aug 7, 2024
Reserved Feb 26, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 22, 2009