CVE-2015-1142857

UnknownEPSS 2.48%

Last modified

CVE-2015-1142857 is a vulnerability of currently unknown severity. On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, additionally Multiple vendor NIC firmware is affected.. EPSS estimates a 2.48% chance of exploitation in the next 30 days.

Description

On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, additionally Multiple vendor NIC firmware is affected.

Metrics

EPSS Probability
2.48%

82.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelX710 FirmwareAll versions
Intel82599 FirmwareAll versions
IntelX540 FirmwareAll versions
IntelI350 FirmwareAll versions
Intel82576 FirmwareAll versions
LinuxLinux Kernel IxgbeAll versions
LinuxLinux Kernel I40e\/I40evfAll versions
DpdkDpdkAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-1142857?
On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, additionally Multiple vendor NIC firmware is affected.
How severe is CVE-2015-1142857?
Severity scoring for CVE-2015-1142857 is pending analysis. The EPSS model estimates a 2.48% probability of exploitation in the next 30 days.
How do I fix CVE-2015-1142857?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-1142857?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST