Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-8612

Published: September 21, 2024Last modified: October 9, 2024

Description

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

Severity score breakdown

ParameterValue
Base score3.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSqemuUnknown (7.1.0-r4)
StreamqemuUnknown (8.0.2-r0)

References

ON THIS PAGE