CVE-2023-34325

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 5, 2024
Updated: Jan 11, 2024
CWE ID 787

Summary

CVE-2023-34325: A vulnerability was found in the libfsimage component of pygrub, which is used by Xen to inspect guest disks. This issue is derived from an outdated version of grub-legacy code and affects libfsimage's parsing capability for several filesystems. The Xen Security Team reported a stack buffer overflow issue, raising concerns about running libfsimage against guest-controlled input with super user privileges. This vulnerability, distinct from CVE-2023-4949, targets the Xen-specific copy of libfsimage. Affected users are advised to follow the resolution steps provided in the advisory to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share