Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Jan 12, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Oct 30, 2017 | Dec 8, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 12, 2018 |
| Ubuntu | — | Upgrade qemu-system-mipsUpgrade qemu-system-miscUpgrade qemu-system-ppcUpgrade qemu-system-sparcUpgrade qemu-system-aarch64Upgrade qemu-systemUpgrade qemu-system-armUpgrade qemu-kvmUpgrade qemu-system-x86 | Nov 8, 2024 | Jan 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub