PT-2023-22809 · Unknown · Cloud Hypervisor

Likebreath

·

Published

2023-04-19

·

Updated

2023-05-01

·

CVE-2023-30612

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cloud Hypervisor versions 30.0 through 31.0
Description This issue allows users to close arbitrary open file descriptors in the Cloud Hypervisor process via sending malicious HTTP requests through the HTTP API socket, potentially causing Deny-of-Service (DoS) and possibly a Use-After-Free (UAF) vulnerability. Users need write access to the API socket file to trigger this issue. The vulnerability was initially detected by the http api fuzzer via oss-fuzz.
Recommendations For Cloud Hypervisor versions 30.0 through 31.0, upgrade to version 30.1 or 31.1 to resolve the issue. For users unable to upgrade, ensure the write access to the API socket file is granted to trusted users only as a mitigation measure.

Exploit

Fix

Missing Authentication

Use After Free

Weakness Enumeration

Related Identifiers

AZL-26278
CVE-2023-30612
GHSA-G6MW-F26H-4JGP

Affected Products

Cloud Hypervisor