PT-2024-3103 · Qemu+11 · Qemu+11

Gerd Hoffmann

·

Published

2024-04-04

·

Updated

2026-06-09

·

CVE-2024-3446

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A double free vulnerability was found in QEMU virtio devices, including virtio-gpu, virtio-serial-bus, and virtio-crypto. The mem reentrancy guard flag does not sufficiently protect against DMA reentrancy issues, which could allow a malicious privileged guest user to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:6964
ALSA-2024:9136
ALT-PU-2024-7560
ALT-PU-2024-9452
ALT-PU-2024-9806
BDU:2024-03304
CESA-2024_6964
CVE-2024-3446
INFSA-2024_6964
INFSA-2024_9136
MGASA-2024-0387
OESA-2024-1491
OESA-2024-1494
OESA-2024-1505
OESA-2024-1510
OESA-2024-1511
OESA-2024-1516
OPENSUSE-SU-2024:13876-1
OPENSUSE-SU-2024_1394-1
OPENSUSE-SU-2024_1438-1
RHSA-2024:6964
RHSA-2024:9136
RHSA-2024_6964
RHSA-2024_9136
RLSA-2024:9136
SUSE-SU-2024:1394-1
SUSE-SU-2024:1438-1
SUSE-SU-2024:1438-2
SUSE-SU-2025:20011-1
USN-7744-1
USN-8412-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Qemu
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu