CVE-2023-34325
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-34325: A vulnerability was found in the libfsimage component of pygrub, which is used by Xen to inspect guest disks. This issue is derived from an outdated version of grub-legacy code and affects libfsimage's parsing capability for several filesystems. The Xen Security Team reported a stack buffer overflow issue, raising concerns about running libfsimage against guest-controlled input with super user privileges. This vulnerability, distinct from CVE-2023-4949, targets the Xen-specific copy of libfsimage. Affected users are advised to follow the resolution steps provided in the advisory to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xen
Affected Vendors
- Xen