Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8fx-hg9x-79mx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.

EPSS

Процентиль: 30%
0.00105
Низкий

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.

CVSS3: 2.8
redhat
почти 6 лет назад

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.

CVSS3: 6.5
nvd
больше 4 лет назад

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() routine while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this flaw to crash the QEMU process, resulting in a denial of service.

CVSS3: 6.5
debian
больше 4 лет назад

In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA imp ...

oracle-oval
больше 4 лет назад

ELSA-2021-9109: qemu security update (IMPORTANT)

EPSS

Процентиль: 30%
0.00105
Низкий

Дефекты

CWE-125