Bug 1216771 (CVE-2023-5088) - VUL-0: CVE-2023-5088: kvm,qemu: improper IDE controller reset can lead to MBR overwrite
Summary: VUL-0: CVE-2023-5088: kvm,qemu: improper IDE controller reset can lead to MBR...
Status: RESOLVED FIXED
Alias: CVE-2023-5088
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/383725/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-5088:6.4:(AV:L...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-01 05:28 UTC by SMASH SMASH
Modified: 2024-01-15 12:43 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-11-01 05:28:05 UTC
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gaining control of L1 at its next reboot.

Reference:
https://lore.kernel.org/all/20230921160712.99521-1-simon.rowe@nutanix.com/T/

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5088