CVE Vulnerabilities

CVE-2023-3255

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 13, 2023 | Modified: Sep 13, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the inflate_buffer function. This could allow a remote authenticated client who is able to send a clipboard to the VNC server to trigger a denial of service.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 8.0.3 (including)
Red Hat Enterprise Linux 8 RedHat virt-devel:rhel-8100020240314161907.e155f54d *
Red Hat Enterprise Linux 8 RedHat virt:rhel-8100020240314161907.e155f54d *
Red Hat Enterprise Linux 9 RedHat qemu-kvm-17:8.2.0-11.el9_4 *
Qemu Ubuntu bionic *
Qemu Ubuntu jammy *
Qemu Ubuntu kinetic *
Qemu Ubuntu lunar *
Qemu Ubuntu trusty *
Qemu Ubuntu xenial *

References