CVE-2020-27173
Last modified
CVE-2020-27173 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. EPSS estimates a 1.51% chance of exploitation in the next 30 days.
Description
In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on the same host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vm-Superio Project | Vm-Superio | < 0.1.1 |
References
- https://github.com/rust-vmm/vm-superio/issues/17Third Party Advisory
- https://github.com/rust-vmm/vm-superio/pull/19Patch, Third Party Advisory
- https://github.com/rust-vmm/vm-superio/issues/17Third Party Advisory
- https://github.com/rust-vmm/vm-superio/pull/19Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27173?
How severe is CVE-2020-27173?
How do I fix CVE-2020-27173?
Are you affected by CVE-2020-27173?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
