Commit Graph

1 Commits

Author SHA1 Message Date
Fiona Ebner
a791b86e0a backport fixes for missing verification for short frames in network tap/tun devices
A malicious guest with virtio-net device could apparently crash the
host [0]. Fixes CVE-2024-41090 and CVE-2024-41091. Reported in the
community forum [1].

[0]: https://seclists.org/oss-sec/2024/q3/110
[1]: https://forum.proxmox.com/threads/151813/

Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
2024-07-26 13:13:20 +02:00