Database/Kernel, userspace & hypervisor
QEMU (IDE/ATAPI): Improper IDE controller reset lets a guest overwrite the host MBR of an attached device
CVE-2023-5088Kernel, userspace & hypervisorcurated
Impact
Improper IDE controller reset lets a guest overwrite the host MBR of an attached device
Who can reach it
Tenant VM guest
What to do
QEMU update + VM restart/live-migration. Also stop exposing raw block devices as IDE to tenant VMs
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.