CVE-2020-27173 Information
Feb 14, 2021
cve
Description
In vm-superio before 0.1.1 the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e. standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place the host can be subject to memory pressure impacting all other VMs running on the same host.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://github.com/rust-vmm/vm-superio/issues/17 https://github.com/rust-vmm/vm-superio/pull/19
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: