First published: Wed May 15 2024(Updated: )
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
gVisor | <6a112c60a257dadac59962e0bc9e9b5aee70b5b6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7258 is classified as a denial of service vulnerability that could lead to a panic in Gvisor Sandbox.
To fix CVE-2023-7258, upgrade to a version of Gvisor that is past commit 6a112c60a.
CVE-2023-7258 affects installations of Google gVisor where users have root access and permission to mount volumes.
If exploited, CVE-2023-7258 could allow an attacker to crash the Gvisor Sandbox, resulting in denial of service.
CVE-2023-7258 specifically involves a bug in the reference counting code related to mount point tracking.