PT-2023-2365 · Qemu+7 · Qemu+7

Soul Chen

·

Published

2023-03-21

·

Updated

2026-01-08

·

CVE-2023-1544

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1685
ALT-PU-2023-1830
ALT-PU-2023-1869
ALT-PU-2023-7821
ALT-PU-2024-13687
ALT-PU-2024-14149
ALT-PU-2024-6235
ALT-PU-2024-7201
AZL-25807
AZL-35166
BDU:2023-02140
CVE-2023-1544
DLA-4144-1
MGASA-2024-0387
OESA-2023-1875
OESA-2023-1894
OESA-2023-1895
OESA-2023-1896
OESA-2023-1897
OPENSUSE-SU-2024_1103-1
ROSA-SA-2025-2641
SUSE-SU-2024:1103-1
SUSE-SU-2024_1103-1
SUSE-SU-2025:4523-1
SUSE-SU-2026:0043-1
SUSE-SU-2026:0070-1
USN-6567-1
USN-6567-2

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Qemu
Red Os
Suse
Ubuntu