Lucene search

K
virtuozzoVirtuozzoVZA-2024-037
HistoryAug 19, 2024 - 12:00 a.m.

[Important] [Security] Virtuozzo ReadyKernel Patch 169.0 for Virtuozzo Hybrid Server 7.5

2024-08-1900:00:00
docs.virtuozzo.com
10
virtuozzo
readykernel
patch 169.0
security
update
hybrid server 7.5
vulnerability
cve-2024-36971
network route management
use-after-free

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

The cumulative Virtuozzo ReadyKernel patch was updated with a security fix. The patch applies to all supported kernels of Virtuozzo Hybrid Server 7.5. NOTE: The kernel 3.10.0-1160.80.1.vz7.191.4 has reached the end of its support period. No more ReadyKernel updates are planned for this kernel.
Vulnerability id: CVE-2024-36971
[3.10.0-1160.90.1.vz7.200.7 to 3.10.0-1160.105.1.vz7.214.3] A use-after-free vulnerability in network route management.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low