Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0330

Опубликовано: 06 мар. 2023
Источник: debian
EPSS Низкий

Описание

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:8.0.2+dfsg-1package
qemufixed1:7.2+dfsg-7+deb12u1bookwormpackage
qemufixed1:5.2+dfsg-11+deb11u3bullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2160151

  • Proposed patch: https://lists.nongnu.org/archive/html/qemu-devel/2023-01/msg03411.html

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e49884a90987744ddb54b2fadc770633eb6a4d62 (v8.0.1)

  • See also generic re-entrancy ground work at https://gitlab.com/qemu-project/qemu/-/issues/556

EPSS

Процентиль: 2%
0.00016
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

CVSS3: 5.3
redhat
больше 2 лет назад

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

CVSS3: 5.3
nvd
больше 2 лет назад

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

CVSS3: 6
msrc
2 месяца назад

Описание отсутствует

CVSS3: 9.8
github
больше 2 лет назад

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

EPSS

Процентиль: 2%
0.00016
Низкий