PT-2024-12379 · Unknown · Hypervisor

Published

2024-01-01

·

Updated

2024-04-12

·

CVE-2023-33036

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Hypervisor (affected versions not specified)
Description The issue involves a permanent denial of service (DOS) in the Hypervisor when an untrusted virtual machine (VM) without Power State Coordination Interface (PSCI) support makes a PSCI call. This can cause a NULL pointer dereferencing, leading to a permanent disruption of the hypervisor software. Additionally, there is a buffer overflow flaw causing memory corruption in the data modem during Voice-over-LTE (VoLTE) calls when the Session Description Protocol (SDP) body is non-standard.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2023-33036

Affected Products

Hypervisor