UBUNTU-CVE-2018-1000026
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..
02 / AFFECTED SOFTWARE
Affected packages
9 explicit affected versions
49 explicit affected versions
70 explicit affected versions
30 explicit affected versions
12 explicit affected versions
10 explicit affected versions
31 explicit affected versions
10 explicit affected versions
8 explicit affected versions
44 explicit affected versions
41 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
7 explicit affected versions
7 explicit affected versions
8 explicit affected versions
7 explicit affected versions
1 explicit affected versions
61 explicit affected versions
3 explicit affected versions
128 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..
05 / REFERENCES
Further evidence
- http://lists.openwall.net/netdev/2018/01/16/40
- http://lists.openwall.net/netdev/2018/01/18/96
- https://git.kernel.org/linus/2b16f048729bf35e6c28a40cbfad07239f9dcd90
- https://git.kernel.org/linus/8914a595110a6eca69a5e275b323f5d09e18f4f9
- https://patchwork.ozlabs.org/patch/859410/
- https://ubuntu.com/security/CVE-2018-1000026
- https://ubuntu.com/security/notices/USN-3617-1
- https://ubuntu.com/security/notices/USN-3617-2
- https://ubuntu.com/security/notices/USN-3617-3
- https://ubuntu.com/security/notices/USN-3619-1
- https://ubuntu.com/security/notices/USN-3619-2
- https://ubuntu.com/security/notices/USN-3620-1
- https://ubuntu.com/security/notices/USN-3620-2
- https://ubuntu.com/security/notices/USN-3632-1
- https://www.cve.org/CVERecord?id=CVE-2018-1000026