CVE-2023-30612 is a denial-of-service (DoS) vulnerability affecting Cloud Hypervisor versions 30.0, 31.0, and the upstream main branch. It allows an attacker with write access to the HTTP API socket to crash the hypervisor by sending a malicious HTTP request that closes arbitrary file descriptors. This medium-severity vulnerability (CVSS 4.9) also presents a potential Use-After-Free (UAF) risk. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. Mitigation involves upgrading to versions 30.1 or 31.1, or restricting write access to the API socket to trusted users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
30.0CPE matchmatch criteria | cpe:2.3:a:cloudhypervisor:cloud_hypervisor:30.0:*:*:*:*:rust:*:* | ||
31.1CPE matchmatch criteria | cpe:2.3:a:cloudhypervisor:cloud_hypervisor:31.1:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.