CVE-2023-30612

MEDIUM

Cloud Hypervisor v30.0-31.0 - Denial of Service via HTTP API Socket File Descriptor Manipulation

Title source: llm
STIX 2.1

Description

Cloud hypervisor is a Virtual Machine Monitor for Cloud workloads. This vulnerability allows users to close arbitrary open file descriptors in the Cloud Hypervisor process via sending malicious HTTP request through the HTTP API socket. As a result, the Cloud Hypervisor process can be easily crashed, causing Deny-of-Service (DoS). This can also be a potential Use-After-Free (UAF) vulnerability. Users require to have the write access to the API socket file to trigger this vulnerability. Impacted versions of Cloud Hypervisor include upstream main branch, v31.0, and v30.0. The vulnerability was initially detected by our `http_api_fuzzer` via oss-fuzz. This issue has been addressed in versions 30.1 and 31.1. Users unable to upgrade may mitigate this issue by ensuring the write access to the API socket file is granted to trusted users only.

Scores

CVSS v3 4.0
EPSS 0.0036
EPSS Percentile 27.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306 CWE-416
Status published
Products (2)
cloudhypervisor/cloud_hypervisor 30.0
cloudhypervisor/cloud_hypervisor 31.1
Published Apr 19, 2023
Tracked Since Feb 18, 2026