Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's handling of virtio devices can lead to invalid memory accesses and hangs during the kexec process in a virtual machine. This issue arises because the virtio-console continues to write to the memory-mapped I/O (MMIO) after the associated virtio-pci device has been reset. The problem is exacerbated by the fact that IOMMUs are reset before the devices, causing some devices to become unresponsive. The vulnerability has been addressed by ensuring that all virtio devices are properly reset during the shutdown process.
The vulnerability can cause hangs in virtual machines during the kexec process, along with invalid memory accesses that are rejected, leading to potential memory management issues.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.