Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Agent Mode for Gemini added to Android Studio

      June 24, 2025

      Google’s Agent2Agent protocol finds new home at the Linux Foundation

      June 23, 2025

      Decoding The SVG path Element: Curve And Arc Commands

      June 23, 2025

      This week in AI dev tools: Gemini 2.5 Pro and Flash GA, GitHub Copilot Spaces, and more (June 20, 2025)

      June 20, 2025

      Microsoft is reportedly planning yet more major cuts at Xbox — as early as next week

      June 24, 2025

      Microsoft makes Windows 10 security updates FREE for an extra year — but there’s a catch, and you might not like it

      June 24, 2025

      “Deus Ex” just turned 25 years old and it’s still the best PC game of all time — you only need $2 to play it on practically anything

      June 24, 2025

      Where to buy a Meta Quest 3S Xbox Edition — and why it’s a better bargain than the “normal” Meta Quest 3S

      June 24, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Vite 7.0 Is Out

      June 24, 2025
      Recent

      Vite 7.0 Is Out

      June 24, 2025

      Exploring JavaScript ES2025 Edition

      June 24, 2025

      Mastering Mixed DML Operations in Apex

      June 24, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft is reportedly planning yet more major cuts at Xbox — as early as next week

      June 24, 2025
      Recent

      Microsoft is reportedly planning yet more major cuts at Xbox — as early as next week

      June 24, 2025

      Microsoft makes Windows 10 security updates FREE for an extra year — but there’s a catch, and you might not like it

      June 24, 2025

      “Deus Ex” just turned 25 years old and it’s still the best PC game of all time — you only need $2 to play it on practically anything

      June 24, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Security»From Bypass to Root: Mandiant Red Team Exploits CVE-2025-2171 and CVE-2025-2172 in Aviatrix Cloud Controller

    From Bypass to Root: Mandiant Red Team Exploits CVE-2025-2171 and CVE-2025-2172 in Aviatrix Cloud Controller

    June 23, 2025

    From Bypass to Root: Mandiant Red Team Exploits CVE-2025-2171 and CVE-2025-2172 in Aviatrix Cloud Controller

    Mandiant successfully breached a fully patched instance of the Aviatrix Controller—a central component in Software-Defined Networking (SDN) architectures—by chaining together multiple vulnerabilities …
    Read more


    Published Date:
    Jun 24, 2025 (48 minutes ago)

    Vulnerabilities has been mentioned in this article.

    CVE-2025-52562

    CVE-2025-2172

    CVE-2025-2171

    CVE-2024-50603

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCritical Convoy Flaw (CVE-2025-52562, CVSS 10.0): Unauthenticated Remote Code Execution on KVM Servers!
    Next Article No Patch, Full Exploit: CVSS 9.9 RCE & IDOR Flaws in InnoShop eCommerce Platform

    Related Posts

    Security

    Rogue WordPress Plugin Unmasked: Stealthy Malware Skims Credit Cards & Steals Credentials

    June 24, 2025
    Security

    Urgent Advantech Alert: Critical Flaws (CVSS 9.6) Expose Industrial Automation to Remote Takeover, PoC Releases

    June 24, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Canonical Dropping Bazaar Support from Launchpad

    Linux

    CVE-2025-21468 – Cisco Firewall Memory Corruption Buffer Overflow

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-49598 – Conda-Forge CI Setup Arbitrary Code Execution

    Common Vulnerabilities and Exposures (CVEs)

    I tested Dell’s latest 2-in-1 laptop, and it’s a big-screen powerhouse (that’s on sale)

    News & Updates

    Highlights

    CVE-2022-50228 – QEMU KVM SVM Invalid Interrupt Injection Vulnerability

    June 18, 2025

    CVE ID : CVE-2022-50228

    Published : June 18, 2025, 11:15 a.m. | 3 hours, 16 minutes ago

    Description : In the Linux kernel, the following vulnerability has been resolved:

    KVM: SVM: Don’t BUG if userspace injects an interrupt with GIF=0

    Don’t BUG/WARN on interrupt injection due to GIF being cleared,
    since it’s trivial for userspace to force the situation via
    KVM_SET_VCPU_EVENTS (even if having at least a WARN there would be correct
    for KVM internally generated injections).

    kernel BUG at arch/x86/kvm/svm/svm.c:3386!
    invalid opcode: 0000 [#1] SMP
    CPU: 15 PID: 926 Comm: smm_test Not tainted 5.17.0-rc3+ #264
    Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
    RIP: 0010:svm_inject_irq+0xab/0xb0 [kvm_amd]
    Code: 0b 0f 1f 00 0f 1f 44 00 00 80 3d ac b3 01 00 00 55 48 89 f5 53
    RSP: 0018:ffffc90000b37d88 EFLAGS: 00010246
    RAX: 0000000000000000 RBX: ffff88810a234ac0 RCX: 0000000000000006
    RDX: 0000000000000000 RSI: ffffc90000b37df7 RDI: ffff88810a234ac0
    RBP: ffffc90000b37df7 R08: ffff88810a1fa410 R09: 0000000000000000
    R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
    R13: ffff888109571000 R14: ffff88810a234ac0 R15: 0000000000000000
    FS: 0000000001821380(0000) GS:ffff88846fdc0000(0000) knlGS:0000000000000000
    CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
    CR2: 00007f74fc550008 CR3: 000000010a6fe000 CR4: 0000000000350ea0
    Call Trace:

    inject_pending_event+0x2f7/0x4c0 [kvm]
    kvm_arch_vcpu_ioctl_run+0x791/0x17a0 [kvm]
    kvm_vcpu_ioctl+0x26d/0x650 [kvm]
    __x64_sys_ioctl+0x82/0xb0
    do_syscall_64+0x3b/0xc0
    entry_SYSCALL_64_after_hwframe+0x44/0xae

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Coinbase Details Insider Data Theft in Remarkable Disclosure

    May 15, 2025

    SolydXK Linux is a Debian-based operating system

    May 2, 2025

    U.S. House Bans WhatsApp on Official Devices Over Security and Data Protection Issues

    June 24, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.