NA

CVE-2024-3567

Published: 10/04/2024 Updated: 10/06/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

qemu qemu 9.0.0

redhat enterprise linux 9.0

Vendor Advisories

Debian Bug report logs - #1068822 qemu: CVE-2024-3567 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 11 Apr 2024 15:48:03 UTC Severity: important Tags: security, upstream Forwarded to gitl ...