PT-2023-9392 · Linux+4 · Linux Kernel+4

Ferdinand Nölscher

·

Published

2023-10-12

·

Updated

2024-09-11

·

CVE-2023-34325

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions (affected versions not specified) Linux kernel versions (affected versions not specified)
Description The issue is related to insufficient input validation in the libfsimage component of the Xen hypervisor and Linux kernel. This could allow an attacker to impact the confidentiality, integrity, and availability of data.
Recommendations For Xen, update to a version that includes the fix for this issue. For Linux kernel, apply the necessary patches or configuration changes to address the insufficient input validation in the libfsimage component. As a temporary workaround, consider restricting access to the libfsimage component until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07006
CVE-2023-34325
OPENSUSE-SU-2023_4054-1
OPENSUSE-SU-2023_4055-1
OPENSUSE-SU-2023_4174-1
OPENSUSE-SU-2023_4475-1
OPENSUSE-SU-2023_4476-1
OPENSUSE-SU-2024:13442-1
SUSE-SU-2023:4054-1
SUSE-SU-2023:4055-1
SUSE-SU-2023:4174-1
SUSE-SU-2023:4183-1
SUSE-SU-2023:4184-1
SUSE-SU-2023:4185-1
SUSE-SU-2023:4475-1
SUSE-SU-2023:4476-1

Affected Products

Debian
Linux Kernel
Red Os
Suse
Xen