PT-2024-15255 · Google+1 · Gvisor Sandbox+1

Published

2024-05-15

·

Updated

2025-07-22

·

CVE-2023-7258

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gvisor Sandbox (affected versions not specified)
Description A denial of service issue exists due to a bug in reference counting code in mount point tracking, which could lead to a panic. This makes it possible for an attacker running as root and with permission to mount volumes to kill the sandbox.
Recommendations We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6 to resolve the issue.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-7258

Affected Products

Debian
Gvisor Sandbox