First published: Mon Sep 25 2023(Updated: )
A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel. This issue may result in a denial of service from guest to host via zero length descriptor.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <5.13 | 5.13 |
Linux Kernel | <=5.12.19 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.21-1 6.12.22-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5158 is a vulnerability that affects the vringh_kiov_advance function in the host side of a virtio ring in the Linux Kernel.
CVE-2023-5158 has a severity rating of 6.5, which is considered medium.
The affected software of CVE-2023-5158 is the Linux Kernel version up to but excluding 5.13.
CVE-2023-5158 may result in a denial of service from guest to host via zero length descriptor.
To fix the CVE-2023-5158 vulnerability, update the Linux Kernel to version 5.13 or later.