GPU VulnDB

Database/Kernel, userspace & hypervisor

VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write): A malicious actor inside a VM

CVE-2024-22273Kernel, userspace & hypervisorcurated

Impact

A malicious actor inside a VM with storage controllers enabled triggers an out-of-bounds read/write and, chained with other issues, executes code on the hypervisor. That is a guest-to-host escape - the boundary your entire multi-tenant model rests on.

Who can reach it

A tenant with control of a VM on the host. Requires storage controllers enabled, which is the default.

What to do

Patch ESXi and reboot the host. Hosts with GPUs in passthrough cannot be live-migrated the way ordinary VMs can, so this is a drain-and-reboot per host with real workload downtime - plan it as a rolling maintenance pass across the cluster. Prioritise above ordinary ESXi patches: escape-class bugs invalidate tenant isolation, and on GPU hosts the co-tenants are high-value.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.