PT-2023-9392 · Linux+4 · Linux Kernel+4
Ferdinand Nölscher
·
Publicado
2023-10-12
·
Atualizado
2024-09-11
·
CVE-2023-34325
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen versions (affected versions not specified)
Linux kernel versions (affected versions not specified)
Description
The issue is related to insufficient input validation in the libfsimage component of the Xen hypervisor and Linux kernel. This could allow an attacker to impact the confidentiality, integrity, and availability of data.
Recommendations
For Xen, update to a version that includes the fix for this issue.
For Linux kernel, apply the necessary patches or configuration changes to address the insufficient input validation in the libfsimage component.
As a temporary workaround, consider restricting access to the libfsimage component until a patch is available.
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Linux Kernel
Red Os
Suse
Xen