Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-26328
HistoryFeb 19, 2024 - 5:15 a.m.

Code injection

2024-02-1905:15:00
PRIOn knowledge base
www.prio-n.com
8
qemu
code injection
pci_sriov_total_vf
nvme
security issue

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%