Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfxg-46gm-p35h

Опубликовано: 14 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

EPSS

Процентиль: 10%
0.00047
Низкий

7.4 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 1 года назад

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

CVSS3: 7.4
redhat
больше 1 года назад

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

CVSS3: 7.4
nvd
около 1 года назад

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

CVSS3: 7.4
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 7.4
debian
около 1 года назад

A heap buffer overflow was found in the virtio-snd device in QEMU. Whe ...

EPSS

Процентиль: 10%
0.00047
Низкий

7.4 High

CVSS3

Дефекты

CWE-122