PT-2013-2223 · Linux+3 · Linux Kernel+3

Publicado

2013-02-20

·

Atualizado

2023-02-13

·

CVE-2013-0311

CVSS v2.0

6.5

Média

VetorAV:A/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.7
Description The issue arises from the translate desc function in drivers/vhost/vhost.c, which does not properly handle cross-region descriptors. This allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.
Recommendations For Linux kernel versions prior to 3.7, update to version 3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to KVM guest OS privileges to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2013_0496
CVE-2013-0311
OPENSUSE-SU-2013_1187-1
RHSA-2013:0496
RHSA-2013:0579
RHSA-2013:0882
RHSA-2013:0928
RHSA-2013_0496
SUSE-SU-2015:0481-1
USN-1756-1
USN-1760-1
USN-1767-1
USN-1768-1
USN-1769-1
USN-1774-1
USN-1778-1
USN-1781-1

Produtos afetados

Centos
Linux Kernel
Red Hat
Suse