ZeroHour

CVE-2018-1000026

CVSS 3.1
7.7 high
EPSS
4%p90
Published
()
Modified
Description

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

Vendors
linuxcanonicalredhatdebian
Products
linux kernel, ubuntu linux, enterprise linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, debian linux
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.