HIGH · 7.9

CVE-2024-11149

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

Vulnerability Description

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

CVSS Score

7.9

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
OpenbsdOpenbsd< 7.4

References

FAQ

What is CVE-2024-11149?

CVE-2024-11149 is a vulnerability with a CVSS score of 7.9 (HIGH). In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

How severe is CVE-2024-11149?

CVE-2024-11149 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-11149?

Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openbsd.