NA

CVE-2024-26327

Published: 19/02/2024 Updated: 19/04/2024

Vulnerability Summary

An issue exists in QEMU 7.1.0 up to and including 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations.

Vendor Advisories

Debian Bug report logs - #1068819 qemu: CVE-2024-26327 CVE-2024-26328 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 11 Apr 2024 15:45:05 UTC Severity: important Tags: security, upstream Reply o ...
Description<!---->A flaw was found in the SR/IOV emulation support of QEMU The register_vfs() function in hw/pci/pcie_sriovc mishandled the situation where a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF (Virtual Function) implementations This flaw allows a malicious guest to crash QEMU and cause a denial of servi ...