CVE-2023-32684 is a low-severity vulnerability affecting Lima, a tool for running Linux virtual machines, primarily on macOS. Prior to version 0.16.0, a malicious disk image within a Lima VM could read a single host filesystem file, even without a mounted host filesystem. Exploitation requires an attacker to embed a target file path in a malicious disk image, making it a complex attack with limited impact, as Lima does not run as root and cannot read entire disks. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.16.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:lima:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.