VulnerabilityModified
CVE-2015-3215
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options.
HIGH 7.5EPSS 1.80%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/virtio-win
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-1043.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1044.htmlVendor Advisory
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/723416fa4210b7464b28eab89cc76252e6193ac1Patch, Third Party Advisory
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/fbfa4d1083ea84c5429992ca3e996d7d4fbc8238Patch, Third Party Advisory
- https://www.redhat.com/security/data/cve/CVE-2015-3215.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1043.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1044.htmlVendor Advisory
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/723416fa4210b7464b28eab89cc76252e6193ac1Patch, Third Party Advisory
- https://github.com/YanVugenfirer/kvm-guest-drivers-windows/commit/fbfa4d1083ea84c5429992ca3e996d7d4fbc8238Patch, Third Party Advisory
- https://www.redhat.com/security/data/cve/CVE-2015-3215.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.