Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-3301
HistorySep 13, 2023 - 5:15 p.m.

CVE-2023-3301

2023-09-1317:15:10
Debian Security Bug Tracker
security-tracker.debian.org
17
qemu
hot-unplug
race scenario
denial of service
net device
virtio-net
pci backend

5.6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

OSVersionArchitecturePackageVersionFilename
Debian12allqemu< 1:7.2+dfsg-7+deb12u1qemu_1:7.2+dfsg-7+deb12u1_all.deb
Debian11allqemu< 1:5.2+dfsg-11+deb11u3qemu_1:5.2+dfsg-11+deb11u3_all.deb
Debian999allqemu< 1:8.0.3+dfsg-1qemu_1:8.0.3+dfsg-1_all.deb
Debian13allqemu< 1:8.0.3+dfsg-1qemu_1:8.0.3+dfsg-1_all.deb

5.6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%