Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-40360

Опубликовано: 14 авг. 2023
Источник: debian
EPSS Низкий

Описание

QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:8.0.4+dfsg-2package
qemunot-affectedbookwormpackage
qemunot-affectedbullseyepackage
qemunot-affectedbusterpackage

Примечания

  • https://gitlab.com/qemu-project/qemu/-/issues/1815

  • Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/73064edfb864743cde2c08f319609344af02aeb3 (v8.0.0-rc0)

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6c8f8456cb0b239812dee5211881426496da7b98 (v8.1.0-rc3)

EPSS

Процентиль: 6%
0.00028
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.

CVSS3: 6
redhat
почти 2 года назад

QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.

CVSS3: 5.5
nvd
почти 2 года назад

QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.

CVSS3: 5.5
github
почти 2 года назад

QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.

CVSS3: 5.5
fstec
почти 2 года назад

Уязвимость функции nvme_directive_receive() виртуального устройства NVMe эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 6%
0.00028
Низкий