LWN.net Logo

hyper-v: denial of service

Package(s):Hyper-V CVE #(s):CVE-2012-2669
Created:November 22, 2012 Updated:November 28, 2012
Description:

From the openSUSE advisory:

The source code without this patch caused hv_kvp_daemon to exit when it processed a spoofed Netlink packet which has been sent from an untrusted local user. Now Netlink messages with a non-zero nl_pid source address are ignored and a warning is printed into the syslog. This fixes the previous change from CVE-2012-2669.

Alerts:
openSUSE openSUSE-SU-2012:1526-1 2012-11-22
Ubuntu USN-1719-1 2013-02-12
Ubuntu USN-1720-1 2013-02-12
Ubuntu USN-1726-1 2013-02-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds