Описание
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| qemu | fixed | 1:11.0.0+ds-1 | package | |
| qemu | fixed | 1:10.0.10+ds-0+deb13u1 | trixie | package |
| qemu | no-dsa | bookworm | package | |
| qemu | postponed | bullseye | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2292089
https://www.zerodayinitiative.com/advisories/ZDI-24-1382/
https://gitlab.com/qemu-project/qemu/-/issues/3090
Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4862d2c95104d9fd0430cc003c205094f8ada1f9 (v11.0.0-rc2)
Связанные уязвимости
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
Уязвимость реализации виртуального адаптера хост-шины LSI53C895A SCSI эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код