Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54566

Опубликовано: 25 июл. 2025
Источник: redhat
CVSS3: 4.2

Описание

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

A flaw was found in QEMU. A migration state inconsistency within the pcie_sriov emulation code allows an attacker with adjacent network access to trigger unexpected behavior. This condition arises from a state mismatch during migration processes, which can potentially lead to resource exhaustion. The vulnerability allows for exploitation via a malformed migration data stream. This issue can result in a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qemu-kvmFix deferred
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 8virt-devel:rhel/qemu-kvmNot affected
Red Hat Enterprise Linux 8virt:rhel/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:8.2/qemu-kvmNot affected
Red Hat Enterprise Linux 9qemu-kvmNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-642
https://bugzilla.redhat.com/show_bug.cgi?id=2383338qemu: QEMU SR-IOV Migration Inconsistency

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
13 дней назад

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

CVSS3: 4.2
nvd
13 дней назад

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

CVSS3: 4.2
debian
13 дней назад

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state incon ...

CVSS3: 4.2
github
13 дней назад

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

4.2 Medium

CVSS3