Vulnerability Description
An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 6.2.8 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LS
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.8Patch
- https://github.com/torvalds/linux/commit/112e66017bff7f2837030f34c2bc19501e9212dRelease Notes
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
- https://security.netapp.com/advisory/ntap-20230511-0007/
- http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LS
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.8Patch
- https://github.com/torvalds/linux/commit/112e66017bff7f2837030f34c2bc19501e9212dRelease Notes
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
- https://security.netapp.com/advisory/ntap-20230511-0007/
FAQ
What is CVE-2023-30456?
CVE-2023-30456 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.
How severe is CVE-2023-30456?
CVE-2023-30456 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30456?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.