Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | May 2, 2007 |
| F5 Big Ip | — | — | Feb 16, 2017 | May 2, 2007 |
| Freebsd | — | Upgrade qemu-develUpgrade qemu | Dec 10, 2025 | May 1, 2007 |
| Oracle_linux | — | Upgrade xen-develUpgrade xenUpgrade xen-libs | Oct 16, 2024 | May 2, 2007 |
| Suse | — | Upgrade xen-tools-domUUpgrade xenUpgrade xen-doc-htmlUpgrade xen-libs-32bitUpgrade xen-develUpgrade xen-toolsUpgrade xen-libsUpgrade xen-doc-pdfUpgrade xen-kmp-defaultUpgrade xen-kmp-pae | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade kvmUpgrade qemuUpgrade xen-3.1 | Nov 19, 2024 | May 2, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub