CVE-2023-7258 - CVE House
Back to Database
Status published Medium CVE-2023-7258

Denial-of-Service in Gvisor

Vulnerability Description

A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-7258

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Gvisor
Vulnerable Versions:
0b983ff832b175e406f4f9b1a3868457bb1ceb7b

Timeline

Official Publish: May 15th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H

Weaknesses (CWE)