Описание
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
qemu | fixed | 1:8.0.2+dfsg-1 | package | |
qemu | fixed | 1:7.2+dfsg-7+deb12u1 | bookworm | package |
qemu | fixed | 1:5.2+dfsg-11+deb11u3 | bullseye | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2160151
Proposed patch: https://lists.nongnu.org/archive/html/qemu-devel/2023-01/msg03411.html
Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e49884a90987744ddb54b2fadc770633eb6a4d62 (v8.0.1)
See also generic re-entrancy ground work at https://gitlab.com/qemu-project/qemu/-/issues/556
EPSS
Связанные уязвимости
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.
EPSS