CVE-2023-2700

CWE-401Memory Leak9 documents8 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 89.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15
Latest updateMay 31

Description

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianlibvirt< 9.0.0-4+2
Ubuntulibvirt< 8.0.0-1ubuntu7.5
CVEListV5libvirtlibvirt-4.5.0
NVDredhat/libvirt4.5.0

Also affects: Fedora 38, Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
OSV
libvirt vulnerabilities2023-05-31
GHSA
GHSA-v972-h57q-v8pw: A vulnerability was found in libvirt2023-05-16
CVEList
CVE-2023-2700: A vulnerability was found in libvirt2023-05-15
OSV
CVE-2023-2700: A vulnerability was found in libvirt2023-05-15

📋Vendor Advisories

4
Ubuntu
libvirt vulnerabilities2023-05-31
Red Hat
libvirt: Memory leak in virPCIVirtualFunctionList cleanup2023-05-15
Microsoft
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtual2023-05-09
Debian
CVE-2023-2700: libvirt - A vulnerability was found in libvirt. This security flaw ouccers due to repeated...2023
CVE-2023-2700 (MEDIUM CVSS 5.5) | A vulnerability was found in libvir | cvebase.io