Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10739
HistoryJan 15, 2019 - 8:51 a.m.

Authorization Bypass

2019-01-1508:51:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.0004 Low

EPSS

Percentile

5.1%

qemu-kvm is vulnerable to authorization bypass attacks. The vulnerability exists through a buffer overflow in the SCSI implementation in QEMU, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

References