A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Aug 25, 2022 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Aug 16, 2022 | Aug 14, 2022 |
| Suse | — | Upgrade qemu-hw-display-virtio-gpuUpgrade qemu-ui-openglUpgrade qemu-ui-spice-coreUpgrade qemu-guest-agentUpgrade qemu-audio-ossUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-ksmUpgrade qemu-armUpgrade qemu-ipxeUpgrade qemu-block-iscsiUpgrade qemu-langUpgrade qemu-hw-display-qxlUpgrade qemu-seabiosUpgrade qemu-chardev-spiceUpgrade qemu-accel-tcg-x86Upgrade qemu-skibootUpgrade qemu-block-sshUpgrade qemu-ui-cursesUpgrade qemu-ui-spice-appUpgrade qemu-audio-spiceUpgrade qemu-ppcUpgrade qemu-hw-usb-redirectUpgrade qemu-audio-paUpgrade qemu-block-rbdUpgrade qemu-sgabiosUpgrade qemu-microvmUpgrade qemu-vgabiosUpgrade qemu-s390Upgrade qemu-chardev-baumUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-toolsUpgrade qemu-kvmUpgrade qemu-audio-alsaUpgrade qemu-ui-sdlUpgrade qemuUpgrade qemu-x86Upgrade qemu-hw-usb-hostUpgrade qemu-SLOFUpgrade qemu-ui-gtkUpgrade qemu-hw-usb-smartcardUpgrade qemu-s390xUpgrade qemu-block-curlUpgrade qemu-audio-sdl | Oct 26, 2022 | Aug 25, 2022 |
| Ubuntu | — | Upgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-system-sparcUpgrade qemu-system-x86-xenUpgrade qemu-system-s390xUpgrade qemu-system-mipsUpgrade qemu-system-x86-microvmUpgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system | Mar 22, 2023 | Aug 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub