{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-10-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"1023798","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023798"},{"name":"RHSA-2010:0476","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0476.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.edge.launchpad.net/ubuntu/+source/qemu-kvm/+bug/458521"},{"name":"ADV-2010-0760","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0760"},{"name":"[qemu-devel] 20091029 Re: qemu-kvm-0.11 regression, crashes on older guests with virtio network","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.gnu.org/archive/html/qemu-devel/2009-10/msg02480.html"},{"name":"oval:org.mitre.oval:def:11143","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11143"},{"tags":["x_refsource_CONFIRM"],"url":"https://patchwork.kernel.org/patch/56479/"},{"name":"[qemu-devel] 20091029 [PATCH] whitelist host virtio networking features [was Re: qemu-kvm-0.11 regression, crashes on older ...]","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.gnu.org/archive/html/qemu-devel/2009-10/msg02495.html"},{"name":"RHSA-2010:0271","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0271.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=virt/kvm/qemu-kvm.git%3Ba=commit%3Bh=184bd0484533b725194fa517ddc271ffd74da7c9"},{"name":"[oss-security] 20100329 CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux virtio-net driver","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2010/03/29/4"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=577218"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-07T00:59:38.986Z"},"title":"CVE Program Container","references":[{"name":"1023798","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023798"},{"name":"RHSA-2010:0476","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0476.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.edge.launchpad.net/ubuntu/+source/qemu-kvm/+bug/458521"},{"name":"ADV-2010-0760","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0760"},{"name":"[qemu-devel] 20091029 Re: qemu-kvm-0.11 regression, crashes on older guests with virtio network","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.gnu.org/archive/html/qemu-devel/2009-10/msg02480.html"},{"name":"oval:org.mitre.oval:def:11143","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11143"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://patchwork.kernel.org/patch/56479/"},{"name":"[qemu-devel] 20091029 [PATCH] whitelist host virtio networking features [was Re: qemu-kvm-0.11 regression, crashes on older ...]","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.gnu.org/archive/html/qemu-devel/2009-10/msg02495.html"},{"name":"RHSA-2010:0271","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2010-0271.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=virt/kvm/qemu-kvm.git%3Ba=commit%3Bh=184bd0484533b725194fa517ddc271ffd74da7c9"},{"name":"[oss-security] 20100329 CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux virtio-net driver","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2010/03/29/4"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=577218"}]}]},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2010-0741","datePublished":"2010-04-12T18:00:00.000Z","dateReserved":"2010-02-26T00:00:00.000Z","dateUpdated":"2024-08-07T00:59:38.986Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}