Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-4135

Опубликовано: 04 авг. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6

Описание

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

1:8.1.3+ds-1ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
lunar

not-affected

code not present
mantic

released

1:8.0.4+dfsg-1ubuntu3.23.10.2

Показывать по

EPSS

Процентиль: 1%
0.00012
Низкий

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
redhat
почти 2 года назад

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.

CVSS3: 6
nvd
почти 2 года назад

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.

CVSS3: 6
debian
почти 2 года назад

A heap out-of-bounds memory read flaw was found in the virtual nvme de ...

CVSS3: 6
github
почти 2 года назад

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость функции nvme_fdp_events() виртуального устройства NVMe эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 1%
0.00012
Низкий

6 Medium

CVSS3