CVE Vulnerabilities

CVE-2024-24474

Published: Feb 20, 2024 | Modified: Jun 10, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because of an underflow of async_len.

Affected Software

Name Vendor Start Version End Version
Qemu Ubuntu bionic *
Qemu Ubuntu focal *
Qemu Ubuntu jammy *
Qemu Ubuntu mantic *
Qemu Ubuntu trusty *
Qemu Ubuntu upstream *
Qemu Ubuntu xenial *

References