Alibaba Cloud Linux 3 : 0143: virt:rhel (ALINUX3-SA-2024:0143)

high Nessus Plugin ID 235990

Synopsis

The remote Alibaba Cloud Linux host is missing one or more security updates.

Description

The remote Alibaba Cloud Linux 3 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALINUX3-SA-2024:0143 advisory.

Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities:

CVE-2023-3255:
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service.

CVE-2023-5088:
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1, potentially gaining control of L1 at its next reboot.

CVE-2023-6683:
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.

CVE-2023-6693:
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the `out_sg` variable could be used to read a part of process memory and send it to the wire, causing an information leak.

CVE-2024-2494:
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.

Tenable has extracted the preceding description block directly from the Alibaba Cloud Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://mirrors.aliyun.com/alinux/3/cve/alinux3-sa-20240143.xml

Plugin Details

Severity: High

ID: 235990

File Name: alinux3_sa_2024-0143.nasl

Version: 1.1

Type: local

Published: 5/14/2025

Updated: 5/14/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-5088

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-wireshark-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-img, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-iscsi-direct-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-img-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-libs-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-iscsi-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-nss-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-ui-spice, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-ui-spice-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-rbd-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-qemu-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-core-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-rbd, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-guest-agent, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-curl, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-libs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-guest-agent-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-scsi-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-client, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-devel, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-nodedev-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-secret-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-nwfilter-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-docs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libguestfs-winsupport, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-core-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-ui-opengl, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-scsi, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-iscsi, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-hw-usbredir-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-user-static-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-core, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-ssh, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-logical-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-config-nwfilter, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-iscsi-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-ui-opengl-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-kvm, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-secret, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-qemu, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-curl-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-docs, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-nss, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-network, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-disk, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-core, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-gluster-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-user-static, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-client-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-ssh-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-rbd-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-interface, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-config-network, cpe:/o:alibabacloud:alibaba_cloud_linux_3, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-gluster, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-common-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-logical, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-lock-sanlock-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-iscsi-direct, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-rbd, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-nodedev, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-network-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-hw-usbredir, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-disk-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-lock-sanlock, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-debugsource, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-interface-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-gluster-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-nwfilter, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-mpath-debuginfo, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-tests, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-mpath, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-debugsource, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-daemon-driver-storage-gluster, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-block-iscsi, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:libvirt-wireshark, p-cpe:/a:alibabacloud:alibaba_cloud_linux_3:qemu-kvm-common

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Alibaba/release, Host/Alibaba/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 6/26/2024

Vulnerability Publication Date: 8/25/2023

Reference Information

CVE: CVE-2023-3255, CVE-2023-5088, CVE-2023-6683, CVE-2023-6693, CVE-2024-2494