Qemu

Qemu

428 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.26%
  • Veröffentlicht 12.01.2024 19:15:11
  • Zuletzt bearbeitet 02.05.2025 15:10:54

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading t...

  • EPSS 0.33%
  • Veröffentlicht 02.01.2024 10:15:08
  • Zuletzt bearbeitet 03.11.2025 20:16:07

A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. Th...

  • EPSS 0.38%
  • Veröffentlicht 06.12.2023 07:15:41
  • Zuletzt bearbeitet 21.11.2024 07:59:26

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and open...

  • EPSS 0.23%
  • Veröffentlicht 03.11.2023 14:15:08
  • Zuletzt bearbeitet 03.11.2025 20:16:06

A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL...

  • EPSS 0.26%
  • Veröffentlicht 13.09.2023 17:15:10
  • Zuletzt bearbeitet 21.11.2024 08:16:57

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and c...

  • EPSS 0.24%
  • Veröffentlicht 13.09.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:04

This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750...

  • EPSS 1.89%
  • Veröffentlicht 13.09.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:16:48

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remot...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 11.09.2023 04:15:10
  • Zuletzt bearbeitet 21.11.2024 08:22:36

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.

  • EPSS 0.66%
  • Veröffentlicht 28.08.2023 21:15:07
  • Zuletzt bearbeitet 21.11.2024 05:14:27

An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third par...

  • EPSS 1.41%
  • Veröffentlicht 22.08.2023 19:16:23
  • Zuletzt bearbeitet 21.11.2024 07:13:27

The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest O...