Lima Linux Foundation Lima

Do you want an email whenever new security vulnerabilities are reported in Linux Foundation Lima?

By the Year

In 2024 there have been 0 vulnerabilities in Linux Foundation Lima . Last year Lima had 1 security vulnerability published. Right now, Lima is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 2.50
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Lima vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Linux Foundation Lima Security Vulnerabilities

Lima launches Linux virtual machines, typically on macOS, for running containerd

CVE-2023-32684 2.5 - Low - May 30, 2023

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is mounted from the host. The official templates of Lima and the well-known third party products (Colima, Rancher Desktop, and Finch) are unlikely to be affected by this issue. To exploit this issue, the attacker has to embed the target file path (an absolute or a relative path from the instance directory) in a malicious disk image, as the qcow2 (or vmdk) backing file path string. As Lima refuses to run as the root, it is practically impossible for the attacker to read the entire host disk via `/dev/rdiskN`. Also, practically, the attacker cannot read at least the first 512 bytes (MBR) of the target file. The issue has been patched in Lima in version 0.16.0 by prohibiting using a backing file path in the VM base image.

Files or Directories Accessible to External Parties

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Linux Foundation Lima or by Linux Foundation? Click the Watch button to subscribe.

subscribe