Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6519

Опубликовано: 21 окт. 2024
Источник: debian

Описание

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:11.0.0+ds-1package
qemufixed1:10.0.10+ds-0+deb13u1trixiepackage
qemuno-dsabookwormpackage
qemupostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2292089

  • https://www.zerodayinitiative.com/advisories/ZDI-24-1382/

  • https://gitlab.com/qemu-project/qemu/-/issues/3090

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4862d2c95104d9fd0430cc003c205094f8ada1f9 (v11.0.0-rc2)

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 2 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
redhat
почти 2 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
nvd
почти 2 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
github
почти 2 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
fstec
около 2 лет назад

Уязвимость реализации виртуального адаптера хост-шины LSI53C895A SCSI эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код