Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-42467

Опубликовано: 11 сент. 2023
Источник: redhat
CVSS3: 2.3
EPSS Низкий

Описание

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.

A denial of service vulnerability was found in the qemu package. A division by zero in the scsi_disk_reset function can cause QEMU and the guest to stop immediately.

Отчет

Triggering this bug requires kernel or root privileges in the guest VM because it requires direct hardware access. Anyone who has these privileges could also just perform a regular shutdown of the VM, with only a very slightly different result.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmFix deferred
Red Hat Enterprise Linux 9qemu-kvmFixedRHSA-2024:213530.04.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2238291QEMU: am53c974: denial of service due to division by zero

EPSS

Процентиль: 1%
0.00012
Низкий

2.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.

CVSS3: 5.5
nvd
почти 2 года назад

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.

CVSS3: 5.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
почти 2 года назад

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset ...

CVSS3: 5.5
github
почти 2 года назад

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.

EPSS

Процентиль: 1%
0.00012
Низкий

2.3 Low

CVSS3