PT-2024-3517 · Qemu+7 · Qemu+7

Alexander Bulekov

+1

·

Published

2024-04-04

·

Updated

2026-06-09

·

CVE-2024-3447

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions QEMU (affected versions not specified)
Description A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both s->data count and the size of s->fifo buffer are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-7560
ALT-PU-2024-9452
ALT-PU-2024-9806
AZL-60196
AZL-60901
BDU:2024-03819
CVE-2024-3447
DLA-4144-1
MGASA-2024-0387
OESA-2024-1491
OESA-2024-1494
OESA-2024-1505
OESA-2024-1510
OESA-2024-1511
OESA-2024-1516
OPENSUSE-SU-2024:13876-1
OPENSUSE-SU-2024_1394-1
OPENSUSE-SU-2024_1438-1
OPENSUSE-SU-2025_0692-1
SUSE-SU-2024:1394-1
SUSE-SU-2024:1438-1
SUSE-SU-2024:1438-2
SUSE-SU-2024:3229-1
SUSE-SU-2025:0692-1
SUSE-SU-2025:20011-1
SUSE-SU-2025_0692-1
USN-7744-1
USN-8412-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Qemu
Red Os
Suse
Ubuntu