6.4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:P/A:P
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
0.001 Low
EPSS
Percentile
38.7%
Problem Description:
The e1000 network adapters permit a variety of modifications
to an Ethernet packet when it is being transmitted. These
include the insertion of IP and TCP checksums, insertion
of an Ethernet VLAN header, and TCP segmentation offload
(“TSO”). The e1000 device model uses an on-stack buffer to
generate the modified packet header when simulating these
modifications on transmitted packets.
When TCP segmentation offload is requested for a transmitted
packet, the e1000 device model used a guest-provided value
to determine the size of the on-stack buffer without
validation. The subsequent header generation could overflow
an incorrectly sized buffer or indirect a pointer composed
of stack garbage.
Impact:
A misbehaving bhyve guest could overwrite memory in the
bhyve process on the host.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
FreeBSD | any | noarch | freebsd-kernel | = 12.0 | UNKNOWN |
FreeBSD | any | noarch | freebsd-kernel | < 12.0_9 | UNKNOWN |
6.4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:P/A:P
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
0.001 Low
EPSS
Percentile
38.7%