PT-2023-22809 · Unknown · Cloud Hypervisor
Likebreath
·
Published
2023-04-19
·
Updated
2023-05-01
·
CVE-2023-30612
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Hypervisor versions 30.0 through 31.0
Description
This issue allows users to close arbitrary open file descriptors in the Cloud Hypervisor process via sending malicious HTTP requests through the HTTP API socket, potentially causing Deny-of-Service (DoS) and possibly a Use-After-Free (UAF) vulnerability. Users need write access to the API socket file to trigger this issue. The vulnerability was initially detected by the
http api fuzzer via oss-fuzz.Recommendations
For Cloud Hypervisor versions 30.0 through 31.0, upgrade to version 30.1 or 31.1 to resolve the issue.
For users unable to upgrade, ensure the write access to the API socket file is granted to trusted users only as a mitigation measure.
Exploit
Fix
Missing Authentication
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Hypervisor