CVE-2015-1142857 Information
Feb 14, 2021
cve
Description
On multiple SR-IOV cars it is possible for VF’s assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1 the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0 additionally Multiple vendor NIC firmware is affected.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Reference
http://seclists.org/oss-sec/2015/q4/425 https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00046&languageid=en-fr https://www.usenix.org/system/files/conference/usenixsecurity15/sec15-paper-smolyar.pdf
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
8.6
Share on: