PT-2023-9392 · Linux+4 · Linux Kernel+4

Ferdinand Nölscher

·

Publicado

2023-10-12

·

Atualizado

2024-09-11

·

CVE-2023-34325

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions (affected versions not specified) Linux kernel versions (affected versions not specified)
Description The issue is related to insufficient input validation in the libfsimage component of the Xen hypervisor and Linux kernel. This could allow an attacker to impact the confidentiality, integrity, and availability of data.
Recommendations For Xen, update to a version that includes the fix for this issue. For Linux kernel, apply the necessary patches or configuration changes to address the insufficient input validation in the libfsimage component. As a temporary workaround, consider restricting access to the libfsimage component until a patch is available.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-07006
CVE-2023-34325
OPENSUSE-SU-2023_4054-1
OPENSUSE-SU-2023_4055-1
OPENSUSE-SU-2023_4174-1
OPENSUSE-SU-2023_4475-1
OPENSUSE-SU-2023_4476-1
OPENSUSE-SU-2024:13442-1
SUSE-SU-2023:4054-1
SUSE-SU-2023:4055-1
SUSE-SU-2023:4174-1
SUSE-SU-2023:4183-1
SUSE-SU-2023:4184-1
SUSE-SU-2023:4185-1
SUSE-SU-2023:4475-1
SUSE-SU-2023:4476-1

Produtos afetados

Debian
Linux Kernel
Red Os
Suse
Xen