Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18261
HistoryMay 02, 2019 - 6:36 a.m.

Integer Overflow

2019-05-0206:36:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.001 Low

EPSS

Percentile

26.7%

QEMU is vulnerable to integer overflow attacks. This occurs in the net_tx_pkt_init function in hw/net/net_tx_pkt.c. A local user can cause an application crash via the maximum fragmentation count which also triggers an unchecked multiplication and null pointer dereference as well.

References