Qemu

Qemu

428 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 20.12.2018 23:29:02
  • Zuletzt bearbeitet 21.11.2024 04:00:54

hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

  • EPSS 3.73%
  • Veröffentlicht 20.12.2018 23:29:02
  • Zuletzt bearbeitet 21.11.2024 04:01:03

hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).

  • EPSS 3.88%
  • Veröffentlicht 20.12.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:01:05

QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).

  • EPSS 3.68%
  • Veröffentlicht 20.12.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:54

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.

  • EPSS 0.49%
  • Veröffentlicht 20.12.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:54

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

  • EPSS 0.49%
  • Veröffentlicht 17.12.2018 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:00:54

pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.

  • EPSS 1.08%
  • Veröffentlicht 13.12.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:29

A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the t...

  • EPSS 0.53%
  • Veröffentlicht 13.12.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:48

hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.

  • EPSS 0.4%
  • Veröffentlicht 13.12.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:00

v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.

  • EPSS 0.42%
  • Veröffentlicht 12.12.2018 13:29:02
  • Zuletzt bearbeitet 21.11.2024 03:53:29

A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, thi...