CVE-2023-5090Improper Handling of Exceptional Conditions in Kernel

Severity
5.5MEDIUMNVD
CNA6.0
EPSS
0.0%
top 88.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateJan 9

Description

A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianlinux/linux_kernel< 6.1.64-1+2

Also affects: Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

6
OSV
linux-azure vulnerabilities2024-01-09
OSV
linux-oem-6.1 vulnerabilities2023-11-21
GHSA
GHSA-f67c-8m2w-79hm: A flaw was found in KVM2023-11-06
CVEList
Kernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs2023-11-06
OSV
CVE-2023-5090: A flaw was found in KVM2023-11-06

📋Vendor Advisories

12
Ubuntu
Linux kernel (Azure) vulnerabilities2024-01-09
Ubuntu
Linux kernel (GCP) vulnerabilities2023-12-06
Ubuntu
Linux kernel vulnerabilities2023-11-30
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2023-11-28
Ubuntu
Linux kernel (StarFive) vulnerabilities2023-11-28

💬Community

1
Bugzilla
CVE-2023-5090 kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs2023-11-06
CVE-2023-5090 — Linux Kernel vulnerability | cvebase