Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-0340
HistoryJan 09, 2024 - 12:00 a.m.

CVE-2024-0340

2024-01-0900:00:00
ubuntu.com
ubuntu.com
18
cve-2024-0340
linux kernel
memory initialization
vhost_new_msg
guest operating system
privileged users
kernel memory contents
vhost-net device file
bugzilla
ubuntu
kvm group

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the
Linux kernel, which does not properly initialize memory in messages passed
between virtual guests and the host operating system in the
vhost/vhost.c:vhost_new_msg() function. This issue can allow local
privileged users to read some kernel memory contents when reading from the
/dev/vhost-net device file.

Bugs

Notes

Author Note
Priority reason: On Ubuntu, /dev/vhost-net access requires being in the kvm group (or root).
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlinux< 5.4.0-173.191UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-100.110UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1120.130UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1056.61UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1056.61~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1120.130~18.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1126.133UNKNOWN
ubuntu22.04noarchlinux-azure< 5.15.0-1058.66UNKNOWN
ubuntu20.04noarchlinux-azure-5.15< 5.15.0-1058.66~20.04.2UNKNOWN
ubuntu18.04noarchlinux-azure-5.4< 5.4.0-1126.133~18.04.1UNKNOWN
Rows per page:
1-10 of 471

References

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%