Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1544
HistoryMar 23, 2023 - 12:00 a.m.

CVE-2023-1544

2023-03-2300:00:00
ubuntu.com
ubuntu.com
12
qemu
vmware
paravirtual
rdma
page tables
cq
async events
out-of-bounds

6.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.6%

A flaw was found in the QEMU implementation of VMWare’s paravirtual RDMA
device. This flaw allows a crafted guest driver to allocate and initialize
a huge number of page tables to be used as a ring of descriptors for CQ and
async events, potentially leading to an out-of-bounds read and crash of
QEMU.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchqemu< anyUNKNOWN
ubuntu20.04noarchqemu< 1:4.2-3ubuntu6.28UNKNOWN
ubuntu22.04noarchqemu< 1:6.2+dfsg-2ubuntu6.16UNKNOWN
ubuntu23.04noarchqemu< 1:7.2+dfsg-5ubuntu2.4UNKNOWN
ubuntu23.10noarchqemu< 1:8.0.4+dfsg-1ubuntu3.23.10.2UNKNOWN
ubuntu24.04noarchqemu< 1:8.1.3+ds-1ubuntu1UNKNOWN
ubuntu14.04noarchqemu< anyUNKNOWN
ubuntu16.04noarchqemu< anyUNKNOWN

6.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.6%