CVE-2023-3019
Description
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description QEMU: e1000e: heap use-after-free in e1000e_write_packet_to_guest() CVSS v3: 6.0 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8virt-devel:rhel-8090020231206155326.a75119d5RHSA-2024:01352024-01-10T00:00:00Z Red Hat Enterprise Linux 8virt:rhel-8090020231206155326.a75119d5RHSA-2024:01352024-01-10T00:00:00Zโฆ
Description
QEMU: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
CVSS v3: 6.0 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8090020231206155326.a75119d5 | RHSA-2024:0135 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 8 | virt:rhel-8090020231206155326.a75119d5 | RHSA-2024:0135 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Extended Update Support | virt-devel:rhel-8060020231128234847.ad008a3a | RHSA-2024:0404 | 2024-01-25T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Extended Update Support | virt:rhel-8060020231128234847.ad008a3a | RHSA-2024:0404 | 2024-01-25T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Extended Update Support | virt-devel:rhel-8080020240116113044.63b34585 | RHSA-2024:0569 | 2024-01-30T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Extended Update Support | virt:rhel-8080020240116113044.63b34585 | RHSA-2024:0569 | 2024-01-30T00:00:00Z |
| Red Hat Enterprise Linux 9 | qemu-kvm-17:8.2.0-11.el9_4 | RHSA-2024:2135 | 2024-04-30T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | qemu-kvm | Out of support scope |
| Red Hat Enterprise Linux 7 | qemu-kvm | Out of support scope |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Out of support scope |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/qemu-kvm | Will not fix |
Apply commands
yum update -y virt-devel:rhel
# or:
dnf upgrade -y virt-devel:rhel
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
Red Hat Mixed 4 releases
| Version | Status | Fixed in |
|---|---|---|
| 9.0 | Affected | โ |
| 9 | Fixed | โ |
| 8.0 | Affected | โ |
| 8 | Fixed | โ |
AlmaLinux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | qemu-img-8.2.0-11.el9_4.aarch64.rpm |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 1:8.2.0+ds-1 |
| sid | Fixed | 1:8.2.0+ds-1 |
| forky | Fixed | 1:8.2.0+ds-1 |
| bullseye | Fixed | 1:5.2+dfsg-11+deb11u4 |
| bookworm | Fixed | 1:7.2+dfsg-7+deb12u4 |
Rocky Linux Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | โ |
| 8 | Fixed | โ |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| qemu | qemu | {"endExcluding":"8.2.0"} | 8.2.0 |
References
- https://access.redhat.com/errata/RHSA-2024:2135
- https://access.redhat.com/errata/RHSA-2024:0135
- https://access.redhat.com/errata/RHSA-2024:0404
- https://access.redhat.com/errata/RHSA-2024:0569
- https://access.redhat.com/security/cve/CVE-2023-3019
- https://bugzilla.redhat.com/show_bug.cgi?id=2222351
- https://lists.debian.org/debian-lts-announce/2025/04/msg00042.html
- https://security.netapp.com/advisory/ntap-20230831-0005/
- https://cert-portal.siemens.com/productcert/html/ssa-577017.html
- https://errata.rockylinux.org/RLSA-2024:0135
- https://www.suse.com/security/cve/CVE-2023-3019.html
- https://errata.rockylinux.org/RLSA-2024:2135
- https://security-tracker.debian.org/tracker/CVE-2023-3019
- https://bugzilla.redhat.com/2218486
- https://bugzilla.redhat.com/2222351
- https://bugzilla.redhat.com/2238291
- https://bugzilla.redhat.com/2247283
- https://bugzilla.redhat.com/2254825
- https://errata.almalinux.org/9/ALSA-2024-2135.html
CWEs
CWE-416
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.