PT-2024-6082 · Qemu+10 · Qemu Nbd Server+10

Michal Findra

·

Published

2024-08-02

·

Updated

2025-09-11

·

CVE-2024-7409

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions QEMU NBD Server (affected versions not specified)
Description A flaw was found in the QEMU NBD Server, allowing a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. This issue is related to synchronization errors and can be exploited by a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

ALSA-2024:6964
ALSA-2024:9136
AZL-60094
AZL-60916
BDU:2024-06925
CESA-2024_6964
CVE-2024-7409
DLA-4296-1
INFSA-2024_6964
INFSA-2024_9136
MGASA-2024-0387
OESA-2024-1988
OESA-2024-1989
OESA-2024-1990
OESA-2024-1991
OESA-2024-2027
OPENSUSE-SU-2024:14411-1
OPENSUSE-SU-2024_2983-1
OPENSUSE-SU-2024_3948-1
OPENSUSE-SU-2024_4094-1
OPENSUSE-SU-2024_4304-1
OPENSUSE-SU-2025_0692-1
RHSA-2024:6964
RHSA-2024:7408
RHSA-2024:9136
RHSA-2024:9912
RHSA-2024_6964
RHSA-2024_9136
RLSA-2024:9136
SUSE-SU-2024:2983-1
SUSE-SU-2024:3744-1
SUSE-SU-2024:3948-1
SUSE-SU-2024:4094-1
SUSE-SU-2024:4304-1
SUSE-SU-2024_3948-1
SUSE-SU-2024_4304-1
SUSE-SU-2025:02530-1
SUSE-SU-2025:0692-1
SUSE-SU-2025:20036-1
SUSE-SU-2025:20076-1
SUSE-SU-2025_02530-1
USN-7744-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Qemu Nbd Server
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu