CVE-2024-26328
Published: February 20, 2024Last modified: October 15, 2024
Description
An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | 23 LTS | qemu | Fixed (9.0.2-r0) |
Stream | qemu | Fixed (9.0.0-r0) |
References
- https://lore.kernel.org/all/20240213055345-mutt-send-email-mst%40kernel.org/
- https://security.netapp.com/advisory/ntap-20240419-0010/