Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-4693

Опубликовано: 14 мая 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.

РелизСтатусПримечание
devel

released

9.0.2+ds-4ubuntu8
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
mantic

ignored

end of life, was needs-triage
noble

released

1:8.2.2+ds-0ubuntu1.4

Показывать по

EPSS

Процентиль: 25%
0.00324
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 2 лет назад

A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.

CVSS3: 5.5
nvd
больше 2 лет назад

A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.

CVSS3: 5.5
msrc
6 месяцев назад

Qemu-kvm: virtio-pci: improper release of configure vector leads to guest triggerable crash

CVSS3: 5.5
debian
больше 2 лет назад

A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci ...

CVSS3: 5.5
github
больше 2 лет назад

A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.

EPSS

Процентиль: 25%
0.00324
Низкий

5.5 Medium

CVSS3