Database/Kernel, userspace & hypervisor
QEMU (IDE/ATAPI): Improper IDE controller reset lets a guest overwrite the host MBR of an attached device
CVSS 6.4CVE-2023-5088Kernel, userspace & hypervisorcurated
Impact
Improper IDE controller reset lets a guest overwrite the host MBR of an attached device
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart/live-migration. Also stop exposing raw block devices as IDE to tenant VMs
References
Related entries
- Intel DSA/IAA (idxd): Hardware erratum: direct access to Intel DSA/IAA accelerators by an untrusted application allowsCVE-2024-21823 · Intel DSA/IAA (idxd)Medium
- Linux kernel (drivers/pci): Pm_runtime_get_sync() does not wait for an already-running .runtime_idle() callback, so aCVE-2024-35809 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci/hotplug): Powering off a physical function that still has child virtual functions drops theCVE-2025-37946 · Linux kernel (drivers/pci/hotplug)Medium
- systemd: Privilege escalation via the systemctl `less` pager when sudo-granted systemctl is availableCVE-2023-26604 · systemdMedium
- Linux kernel (net/sched SFQ): Missing limit validation in sch_sfq - out-of-bounds writeCVE-2025-37752 · Linux kernel (net/sched SFQ)Medium
- libssh SCP client: malicious server can write files outside the client's working directoryCVE-2026-0964 · libssh SCP client (server-supplied path handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.