PT-2024-1924 · Qemu+9 · Qemu+9

Published

2024-02-14

·

Updated

2025-12-18

·

CVE-2024-26327

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU versions 7.1.0 through 8.2.1
Description The issue is related to a buffer overflow in the register vfs() function in hw/pci/pcie sriov.c of the QEMU hardware emulator. This occurs when a guest writes NumVFs greater than TotalVFs, leading to a buffer overflow in VF implementations. Exploitation of this issue may allow an attacker to cause a denial of service.
Recommendations For QEMU versions 7.1.0 through 8.2.1, consider disabling the register vfs() function in hw/pci/pcie sriov.c as a temporary workaround until a patch is available. Restrict access to the vulnerable pcie sriov.c module to minimize the risk of exploitation. Avoid using the NumVFs and TotalVFs variables in the affected register vfs() function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:9136
ALT-PU-2024-6223
ALT-PU-2024-6235
ALT-PU-2024-7201
AZL-61716
BDU:2024-01712
CVE-2024-26327
INFSA-2024_9136
MGASA-2024-0387
OPENSUSE-SU-2024_1103-1
RHSA-2024:9136
RHSA-2024_9136
RLSA-2024:9136
SUSE-SU-2024:1103-1
USN-6977-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Qemu
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu