PT-2013-2223 · Linux+3 · Linux Kernel+3

Published

2013-02-20

·

Updated

2023-02-13

·

CVE-2013-0311

CVSS v2.0

6.5

Medium

VectorAV:A/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.7
Description The issue arises from the translate desc function in drivers/vhost/vhost.c, which does not properly handle cross-region descriptors. This allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.
Recommendations For Linux kernel versions prior to 3.7, update to version 3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to KVM guest OS privileges to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2013_0496
CVE-2013-0311
OPENSUSE-SU-2013_1187-1
RHSA-2013:0496
RHSA-2013:0579
RHSA-2013:0882
RHSA-2013:0928
RHSA-2013_0496
SUSE-SU-2015:0481-1
USN-1756-1
USN-1760-1
USN-1767-1
USN-1768-1
USN-1769-1
USN-1774-1
USN-1778-1
USN-1781-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse