CVE-2023-1544 - CERT CVE
ID CVE-2023-1544
Sažetak A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU.
Reference
CVSS
Base: 6.3
Impact: 4.0
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Zadnje važnije ažuriranje 19-04-2024 - 14:15
Objavljeno 23-03-2023 - 20:15