CVE-2024-22273
published 2024-05-21CVE-2024-22273: The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.9th percentile
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 5.1.1 | 5.1.1 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 13.0.0 < 13.5.1 | 13.5.1 |
| vmware | workstation | >= 17.0.0 < 17.5.1 | 17.5.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9mq7-wpm3-gv26: The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability
ghsa_unreviewed·2024-05-21
CVE-2024-22273 [HIGH] CWE-125 GHSA-9mq7-wpm3-gv26: The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
Red Hat
kernel: usb: vhci-hcd: Do not drop references before new references are gained
vendor_redhat·2024-08-23·CVSS 7.0
CVE-2024-43883 [HIGH] CWE-416 kernel: usb: vhci-hcd: Do not drop references before new references are gained
kernel: usb: vhci-hcd: Do not drop references before new references are gained
In the Linux kernel, the following vulnerability has been resolved:
usb: vhci-hcd: Do not drop references before new references are gained
At a few places the driver carries stale pointers
to references that can still be used. Make sure that does not happen.
This strictly speaking closes ZDI-CAN-22273, though there may be
similar races in the driver.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-21
Published