ALT-PU-2024-9452-2
Closed vulnerabilities
BDU:2024-03304
Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю выполнить произвольный код
BDU:2024-03819
Уязвимость функции sdhci_write_dataport эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2024-04887
Уязвимость функции update_sctp_checksum() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-05-03
CVE-2024-3446
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.
- RHSA-2024:6964
- https://access.redhat.com/security/cve/CVE-2024-3446
- RHBZ#2274211
- https://patchew.org/QEMU/20240409105537.18308-1-philmd@linaro.org/
- https://security.netapp.com/advisory/ntap-20250502-0007/
- https://patchew.org/QEMU/20240409105537.18308-1-philmd@linaro.org/
- RHBZ#2274211
- https://access.redhat.com/security/cve/CVE-2024-3446
Modified: 2025-04-26
CVE-2024-3447
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
Modified: 2025-05-06
CVE-2024-3567
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.
- RHSA-2025:4492
- https://access.redhat.com/security/cve/CVE-2024-3567
- https://access.redhat.com/security/cve/CVE-2024-3567
- RHBZ#2274339
- RHBZ#2274339
- https://gitlab.com/qemu-project/qemu/-/issues/2273
- https://gitlab.com/qemu-project/qemu/-/issues/2273
- https://security.netapp.com/advisory/ntap-20240822-0007/