A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57430 | A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition. |
Ubuntu USN |
USN-6497-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6502-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6502-2 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6502-3 | Linux kernel (NVIDIA) vulnerabilities |
Ubuntu USN |
USN-6502-4 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6503-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6520-1 | Linux kernel (StarFive) vulnerabilities |
Ubuntu USN |
USN-6537-1 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-6572-1 | Linux kernel (Azure) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References
History
Wed, 11 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9 |
Wed, 11 Sep 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:enterprise_linux:9::appstream cpe:/a:redhat:enterprise_linux:9::crb cpe:/a:redhat:enterprise_linux:9::nfv cpe:/a:redhat:enterprise_linux:9::realtime cpe:/o:redhat:enterprise_linux:9::baseos |
|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-08T07:10:11.332Z
Reserved: 2023-09-20T15:29:32.106Z
Link: CVE-2023-5090
No data.
Status : Modified
Published: 2023-11-06T11:15:09.670
Modified: 2024-11-21T08:41:02.793
Link: CVE-2023-5090
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN