Denial of Service Vulnerability in IBM PowerKVM
CVE-2016-3044

6.5MEDIUM

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
1 December 2016

Summary

A vulnerability in the Linux kernel component of IBM PowerKVM versions 2.1 prior to 2.1.1.3-65.10 and 3.1 prior to 3.1.0.2 permits guest operating system users to exploit unspecified vectors, leading to a denial of service condition that can cause the host operating system to enter an infinite loop, resulting in system hang and unresponsiveness. This vulnerability poses significant operational risks for environments relying on virtualized infrastructure.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.