The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-emulation/qemu-kvm. | Oct 30, 2017 | Jun 21, 2012 |
| Oracle_linux | — | Upgrade qemu-kvm-toolsUpgrade qemu-imgUpgrade qemu-kvm | Oct 16, 2024 | Jun 21, 2012 |
| Suse | — | Upgrade kvm | Feb 17, 2015 | Jun 21, 2012 |
| Ubuntu | — | Upgrade qemu-kvm-extrasUpgrade qemu-kvmUpgrade qemu-kvm-extras-static | Nov 8, 2024 | Jun 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub