Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-26328
HistoryFeb 19, 2024 - 5:15 a.m.

CVE-2024-26328

2024-02-1905:15:26
Debian Security Bug Tracker
security-tracker.debian.org
4
qemu
pcie sr-iov
nvme controller
mishandled interaction

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

OSVersionArchitecturePackageVersionFilename
Debian12allqemu< 1:7.2+dfsg-7+deb12u6qemu_1:7.2+dfsg-7+deb12u6_all.deb
Debian11allqemu< 1:5.2+dfsg-11+deb11u3qemu_1:5.2+dfsg-11+deb11u3_all.deb
Debian999allqemu< 1:8.2.3+ds-1qemu_1:8.2.3+ds-1_all.deb
Debian13allqemu< 1:8.2.3+ds-1qemu_1:8.2.3+ds-1_all.deb

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%