Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-7409

Опубликовано: 05 авг. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:9.0.2+ds-3package
qemufixed1:7.2+dfsg-7+deb12u8bookwormpackage
qemupostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2302487

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/c8a76dbd90c2f48df89b75bef74917f90a59b623 (v9.1.0-rc2)

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/b9b72cb3ce15b693148bd09cef7e50110566d8a0 (v9.1.0-rc2)

  • Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/3e7ef738c8462c45043a1d39f702a0990406a3b3 (v9.1.0-rc2)

  • Followup to fix (in 1:9.0.2+ds-5): https://lists.nongnu.org/archive/html/qemu-stable/2024-08/msg00101.html

EPSS

Процентиль: 81%
0.01691
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

CVSS3: 7.5
redhat
11 месяцев назад

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

CVSS3: 7.5
nvd
11 месяцев назад

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

CVSS3: 7.5
github
11 месяцев назад

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

oracle-oval
8 месяцев назад

ELSA-2024-12792: virt:kvm_utils3 security update (MODERATE)

EPSS

Процентиль: 81%
0.01691
Низкий