CVE Vulnerabilities

CVE-2023-42467

Divide By Zero

Published: Sep 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
2.3 LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.

Weakness

The product divides a value by zero.

Affected Software

NameVendorStart VersionEnd Version
QemuQemu*8.0.0 (including)
Red Hat Enterprise Linux 9RedHatqemu-kvm-17:8.2.0-11.el9_4*
QemuUbuntubionic*
QemuUbuntudevel*
QemuUbuntulunar*
QemuUbuntumantic*
QemuUbuntunoble*
QemuUbuntuoracular*
QemuUbuntutrusty*
QemuUbuntuxenial*

References