The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade app-emulation/qemu-kvm. | Oct 30, 2017 | Jun 21, 2012 |
| Oracle_linux | — | Upgrade qemu-kvmUpgrade qemu-imgUpgrade qemu-kvm-tools | Oct 16, 2024 | Jun 21, 2012 |
| Suse | — | Upgrade kvm | Feb 17, 2015 | Jun 21, 2012 |
| Ubuntu | — | Upgrade qemu-kvm-extras-staticUpgrade qemu-kvm-extrasUpgrade qemu-kvm | Nov 8, 2024 | Jun 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub