CVE-2023-54007 is a race condition vulnerability in the Linux kernel's vmci_host_poll() function, affecting the VMware VMCI (Virtual Machine Communication Interface) driver. This flaw can lead to a General Protection Fault (GPF) due to a null-pointer dereference. The vulnerability arises from non-atomic reads of context initialization status, allowing vmci_host_poll() to attempt dereferencing an uninitialized context. The severity of this vulnerability is moderate. It requires a race condition to be triggered, which can increase attack complexity. The primary impact is a denial of service (system crash) due to the GPF, which could disrupt virtualized environments. There is no indication of active exploitation for CVE-2023-54007. No public exploit code or Metasploit modules are available, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 3.9CNA affecteddefault affected | |
| Linux | Linux | >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < 2053e93ac15519ed1f1fe6eba79a33a4963be4a3, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < 67e35824f861a05b44b19d38e16a83f653bd9d92, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < 770d30b1355c6c8879973dd054fca9168def182c, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < 85b4aa4eb2e3a0da111fd0a1cdbf00f986ac6b6b, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < ab64bd32b9fac27ff4737d63711b9db5e5462448, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < ae13381da5ff0e8e084c0323c3cc0a945e43e9c7, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < ca0f4ad2b7a36c799213ef0a213eb977a51e03dc, >= 8bf503991f87e32ea42a7bd69b79ba084fddc5d7, < d22b2a35729cb1de311cb650cd67518a24e13fc9CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.