CVE-2024-7409
- EPSS 1.71%
- Veröffentlicht 05.08.2024 14:15:35
- Zuletzt bearbeitet 03.11.2025 19:15:44
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
CVE-2024-6505
- EPSS 0.09%
- Veröffentlicht 05.07.2024 14:15:03
- Zuletzt bearbeitet 21.11.2024 09:49:46
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, pot...
CVE-2024-4693
- EPSS 0.03%
- Veröffentlicht 14.05.2024 15:44:26
- Zuletzt bearbeitet 21.11.2024 09:43:23
A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to cr...
CVE-2024-3567
- EPSS 0.09%
- Veröffentlicht 10.04.2024 15:16:05
- Zuletzt bearbeitet 06.05.2025 09:15:17
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and ca...
CVE-2024-24474
- EPSS 0.47%
- Veröffentlicht 20.02.2024 18:15:52
- Zuletzt bearbeitet 25.06.2025 19:29:42
QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underf...
- EPSS 0.04%
- Veröffentlicht 19.02.2024 05:15:26
- Zuletzt bearbeitet 07.05.2025 12:27:30
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
CVE-2024-26327
- EPSS 0.18%
- Veröffentlicht 19.02.2024 05:15:22
- Zuletzt bearbeitet 07.05.2025 12:27:21
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.
CVE-2023-6683
- EPSS 0.07%
- Veröffentlicht 12.01.2024 19:15:11
- Zuletzt bearbeitet 02.05.2025 15:10:54
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading t...
CVE-2023-6693
- EPSS 0.03%
- Veröffentlicht 02.01.2024 10:15:08
- Zuletzt bearbeitet 03.11.2025 20:16:07
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. Th...
CVE-2023-2861
- EPSS 0.04%
- Veröffentlicht 06.12.2023 07:15:41
- Zuletzt bearbeitet 21.11.2024 07:59:26
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and open...