Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39267
HistoryFeb 15, 2023 - 12:46 a.m.

Out-of-bounds Read

2023-02-1500:46:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
qemu
out-of-bounds read
qxl_phys2virt()
denial of service
vulnerability

0.0004 Low

EPSS

Percentile

14.4%

qemu is vulnerable to Out-of-bounds Read. An out-of-bounds read flaw was found qxl_phys2virt() function which does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.