Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31760
HistoryAug 19, 2021 - 11:32 a.m.

Denial Of Service

2021-08-1911:32:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
qemu
denial of service
vulnerability
spice client

EPSS

0.003

Percentile

71.3%

qemu is vulnerable to denial of service. The vulnerability exists when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full, a malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU.