VMX VMM Limit Restoration Issue
CVE-2024-11149

7.9HIGH

Key Information:

Vendor
OpenBSD
Status
Vendor
CVE Published:
6 December 2024

Summary

OpenBSD version 7.4 prior to errata 014 contains a vulnerability in its virtual machine monitor (vmm) that fails to correctly restore General Descriptor Table Register (GDTR) limits on Intel VMX CPUs. This mismanagement can lead to improper memory handling within virtual machines, potentially allowing for unforeseen interactions or security lapses. Users of OpenBSD should apply the pertinent patches to safeguard their systems from this vulnerability.

Affected Version(s)

OpenBSD 7.4 < 7.4 errata 014

OpenBSD 7.4 errata 014

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.