ZeroHour

CVE-2018-14625

CVSS 3.0
7.0 high
EPSS
<1%p26
Published
()
Modified
Description

A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.

Vendors
linuxcanonicaldebian
Products
linux kernel, ubuntu linux, debian linux
Weakness
CWE-416, CWE-362
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.