• CVE-2024-6505

发布时间: 2024年9月19日

修改时间: 2024年10月12日

概要

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

CVSS v3 指标

NVD openEuler
CVSS评分 6.8 6.8
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required High High
User Interaction None None
Scope Changed Changed
Confidentiality None None
Integrity None None
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3841 qemu security update 2024年9月27日

影响产品

产品 状态
KY3.4-5A qemu Unaffected
KY3.5.2 qemu Fixed
V6 qemu Fixed