CVE-2023-5088 describes a critical bug in QEMU that could allow a malicious guest VM to overwrite the boot code of its host hypervisor (L1) by redirecting I/O operations to offset 0 of the host's virtual disk. This vulnerability, affecting QEMU and Red Hat Enterprise Linux, carries a CVSS score of 7.0 (HIGH) due to its low attack complexity and high potential for confidentiality, integrity, and availability impact. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.2.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.