Lucene search

K
redhatcveRedhat.comRH:CVE-2024-26327
HistoryFeb 19, 2024 - 9:49 a.m.

CVE-2024-26327

2024-02-1909:49:35
redhat.com
access.redhat.com
9
qemu
sr/iov
buffer overflow
denial of service

5.3 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

A flaw was found in the SR/IOV emulation support of QEMU. The register_vfs() function in hw/pci/pcie_sriov.c mishandled the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF (Virtual Function) implementations. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.

5.3 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%