PT-2023-9605 · Qemu+3 · Qemu+3

Published

2023-08-06

·

Updated

2024-06-06

·

CVE-2023-40360

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions 8.0.4 and earlier
Description The issue is related to the nvme directive receive() function in the QEMU NVMe emulator, which accesses a NULL pointer because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled. This can lead to a denial of service.
Recommendations For QEMU versions 8.0.4 and earlier, as a temporary workaround, consider disabling the nvme directive receive() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5203
ALT-PU-2024-6235
ALT-PU-2024-7201
BDU:2024-08735
CVE-2023-40360
USN-6567-1
USN-6567-2

Affected Products

Alt Linux
Linuxmint
Qemu
Ubuntu