Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6519

Опубликовано: 10 окт. 2024
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

Отчет

The qemu-kvm packages shipped in Red Hat Enterprise Linux and RHEL Advanced Virtualization are not affected by this issue because the LSI53C895A device is not enabled. Additionally, LSI53C895A emulation is not used for virtualized production services. Therefore, it is unlikely to be used in association with untrusted guests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qemu-kvmNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmNot affected
Red Hat Enterprise Linux 9qemu-kvmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2292089qemu-kvm: lsi53c895a: use-after-free local privilege escalation vulnerability

EPSS

Процентиль: 3%
0.00016
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 1 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
nvd
около 1 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
debian
около 1 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI H ...

CVSS3: 8.2
github
около 1 года назад

A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.

CVSS3: 8.2
fstec
больше 1 года назад

Уязвимость реализации виртуального адаптера хост-шины LSI53C895A SCSI эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 3%
0.00016
Низкий

8.2 High

CVSS3