Логотип exploitDog
bind:CVE-2024-8612
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8612

Количество 12

Количество 12

ubuntu логотип

CVE-2024-8612

около 1 года назад

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
EPSS: Низкий
redhat логотип

CVE-2024-8612

около 1 года назад

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2024-8612

около 1 года назад

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
EPSS: Низкий
msrc логотип

CVE-2024-8612

3 месяца назад

Qemu-kvm: information leak in virtio devices

EPSS: Низкий
debian логотип

CVE-2024-8612

около 1 года назад

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-c ...

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-whq8-5442-qhw7

около 1 года назад

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
EPSS: Низкий
fstec логотип

BDU:2025-06254

около 1 года назад

Уязвимость компонентов virtio-scsi, virtio-blk, virtio-crypt функции virtqueue_push() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 3.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0692-1

9 месяцев назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4304-1

11 месяцев назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3948-1

около 1 года назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4094-1

12 месяцев назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3744-1

около 1 года назад

Security update for qemu

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-8612

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-8612

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-8612

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
0%
Низкий
около 1 года назад
msrc логотип
CVE-2024-8612

Qemu-kvm: information leak in virtio devices

0%
Низкий
3 месяца назад
debian логотип
CVE-2024-8612

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-c ...

CVSS3: 3.8
0%
Низкий
около 1 года назад
github логотип
GHSA-whq8-5442-qhw7

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

CVSS3: 3.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-06254

Уязвимость компонентов virtio-scsi, virtio-blk, virtio-crypt функции virtqueue_push() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 3.8
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0692-1

Security update for qemu

9 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:4304-1

Security update for qemu

11 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3948-1

Security update for qemu

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4094-1

Security update for qemu

12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3744-1

Security update for qemu

около 1 года назад

Уязвимостей на страницу