[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2336 --- qemu

ID: oval:org.secpod.oval:def:1701933Date: (C)2023-11-24   (M)2024-03-18
Class: PATCHFamily: unix




A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead . This could be used, for example, by L2 guests with a virtual disk stored on a virtual disk of an L1 hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gaining control of L1 at its next reboot

Platform:
Amazon Linux 2
Product:
qemu
ivshmem-tools
qemu-guest-agent
qemu-img
Reference:
ALAS2-2023-2336
CVE-2023-5088
CVE    1
CVE-2023-5088
CPE    5
cpe:/a:qemu:ivshmem-tools
cpe:/a:qemu:qemu
cpe:/a:kvm_group:qemu_guest_agent
cpe:/o:amazon:linux:2
...

© SecPod Technologies