CVE-2023-5088Incorrect Synchronization in Qemu

Severity
7.0HIGHNVD
CNA6.4
EPSS
0.0%
top 97.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 3
Latest updateJan 8

Description

A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gaining control of L1 at its next reboot.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages2 packages

NVDqemu/qemu< 8.2.0
Debianqemu/qemu< 1:5.2+dfsg-11+deb11u4+3

Also affects: Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
CVEList
Qemu: improper ide controller reset can lead to mbr overwrite2023-11-03
OSV
CVE-2023-5088: A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwr2023-11-03
GHSA
GHSA-9627-hqj3-f64h: A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwr2023-11-03

📋Vendor Advisories

4
Ubuntu
QEMU vulnerabilities2024-01-08
Microsoft
Qemu: improper ide controller reset can lead to mbr overwrite2023-11-14
Red Hat
QEMU: improper IDE controller reset can lead to MBR overwrite2023-09-21
Debian
CVE-2023-5088: qemu - A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitr...2023
CVE-2023-5088 — Incorrect Synchronization in Qemu | cvebase