Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3301

Опубликовано: 19 июн. 2023
Источник: redhat
CVSS3: 5.6

Описание

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvm-maOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmWill not fix
Red Hat Enterprise Linux 9qemu-kvmAffected
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevOut of support scope
Red Hat Enterprise Linux 8virt-develFixedRHSA-2023:698014.11.2023
Red Hat Enterprise Linux 8virtFixedRHSA-2023:698014.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2215784QEMU: net: triggerable assertion due to race condition in hot-unplug

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
nvd
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

CVSS3: 5.6
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.6
debian
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a rac ...

CVSS3: 5.6
github
почти 2 года назад

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.

5.6 Medium

CVSS3