PT-2020-16646 · Unknown · Vm-Superio
Published
2020-10-16
·
Updated
2021-07-21
·
CVE-2020-27173
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
vm-superio versions prior to 0.1.1
Description
The serial console FIFO can grow to unlimited memory usage when data is sent to the input source, i.e., standard input. This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on the same host.
Recommendations
For versions prior to 0.1.1, update to version 0.1.1 or later to resolve the issue. As a temporary workaround, consider implementing rate limiting to prevent the host from being subject to memory pressure.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm-Superio