Database/Kernel, userspace & hypervisor
VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write): A malicious actor inside a VM
Impact
A malicious actor inside a VM with storage controllers enabled triggers an out-of-bounds read/write and, chained with other issues, executes code on the hypervisor. That is a guest-to-host escape - the boundary your entire multi-tenant model rests on.
Who can reach it
A tenant with control of a VM on the host. Requires storage controllers enabled, which is the default.
What to do
Patch ESXi and reboot the host. Hosts with GPUs in passthrough cannot be live-migrated the way ordinary VMs can, so this is a drain-and-reboot per host with real workload downtime - plan it as a rolling maintenance pass across the cluster. Prioritise above ordinary ESXi patches: escape-class bugs invalidate tenant isolation, and on GPU hosts the co-tenants are high-value.
References
Related entries
- Linux kernel (net/xfrm): The error path of xfrm_input leaves the secpath entry pointing at poisoned memory, and theCVE-2024-43878 · Linux kernel (net/xfrm)High
- Linux kernel NVMe target authentication (nvmet-auth DH group setup): CtrlCVE-2024-50215 · Linux kernel NVMe target authentication (nvmet-auth DH group setup)High
- OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc LinuxCVE-2024-6387 · OpenSSH (sshd)High
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
- libssh: unchecked OpenSSL error can leave a partially initialized ChaCha20 context in useCVE-2025-5987 · libssh (ChaCha20 cipher context initialization via OpenSSL)High
- OpenSSH scp: file fetched as root with -O and without -p can land setuid or setgidCVE-2026-35385 · OpenSSH scp (legacy SCP protocol mode, -O without -p)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.