Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12127
HistoryJan 15, 2019 - 9:12 a.m.

Denial Of Service (DoS)

2019-01-1509:12:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

24.9%

QEMU is vulnerable to denial of service. Quick Emulator(Qemu) built with the Block driver for iSCSI images support (virtio-blk) is vulnerable to a heap buffer overflow issue. It could occur while processing iSCSI asynchronous I/O ioctl(2) calls. A user inside guest could use this flaw to crash the Qemu process resulting in DoS or potentially leverage it to execute arbitrary code with privileges of the Qemu process on the host.

References