NA

CVE-2023-3180

Published: 03/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

qemu qemu 8.1.0

fedoraproject fedora 38

debian debian linux 10.0

Vendor Advisories

A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ (CVE-2023-3180) ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...