6

CVE-2023-0330

Qemu: lsi53c895a: dma reentrancy issue leads to stack overflow

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qemu ≫ Qemu Version >= 7.2.0 < 7.2.3
Qemu ≫ Qemu Version 8.0.0 Update -
Qemu ≫ Qemu Version 8.0.0 Update rc0
Qemu ≫ Qemu Version 8.0.0 Update rc1
Qemu ≫ Qemu Version 8.0.0 Update rc2
Qemu ≫ Qemu Version 8.0.0 Update rc3
Qemu ≫ Qemu Version 8.0.0 Update rc4
Debian ≫ Debian Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.185
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
patrick@puiterwijk.org 5.3 0.8 4
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/security/cve/CVE-2023-0330
https://bugzilla.redhat.com/show_bug.cgi?id=2160151
https://lists.debian.org/debian-lts-announce/2023/10/msg00006.html
Third Party Advisory
Mailing List
https://lists.nongnu.org/archive/html/qemu-devel/2023-01/msg03411.html
Patch
Mailing List