NA

CVE-2024-3567

Published: 10/04/2024 Updated: 10/04/2024

Vulnerability Summary

A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.

Vendor Advisories

Debian Bug report logs - #1068822 qemu: CVE-2024-3567 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 11 Apr 2024 15:48:03 UTC Severity: important Tags: security, upstream Forwarded to gitl ...