CVE-2023-3019

medium
Published 2024-04-30 ยท Modified 2024-01-10
CVSS v3
6.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.5

Description

A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.

Predictions

Exploit likelihood
65%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description QEMU: e1000e: heap use-after-free in e1000e_write_packet_to_guest() CVSS v3: 6.0 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8virt-devel:rhel-8090020231206155326.a75119d5RHSA-2024:01352024-01-10T00:00:00Z Red Hat Enterprise Linux 8virt:rhel-8090020231206155326.a75119d5RHSA-2024:01352024-01-10T00:00:00Zโ€ฆ

Description

QEMU: e1000e: heap use-after-free in e1000e_write_packet_to_guest()

CVSS v3: 6.0 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8virt-devel:rhel-8090020231206155326.a75119d5RHSA-2024:01352024-01-10T00:00:00Z
Red Hat Enterprise Linux 8virt:rhel-8090020231206155326.a75119d5RHSA-2024:01352024-01-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportvirt-devel:rhel-8060020231128234847.ad008a3aRHSA-2024:04042024-01-25T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportvirt:rhel-8060020231128234847.ad008a3aRHSA-2024:04042024-01-25T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportvirt-devel:rhel-8080020240116113044.63b34585RHSA-2024:05692024-01-30T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportvirt:rhel-8080020240116113044.63b34585RHSA-2024:05692024-01-30T00:00:00Z
Red Hat Enterprise Linux 9qemu-kvm-17:8.2.0-11.el9_4RHSA-2024:21352024-04-30T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvm-maOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmWill not fix

Apply commands

bash fix
Apply RHSA-2024:0135 for Red Hat Enterprise Linux 8
yum update -y virt-devel:rhel
# or:
dnf upgrade -y virt-devel:rhel

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
redhat Red Hat Mixed 4 releases
VersionStatusFixed in
9.0 Affected โ€”
9 Fixed โ€”
8.0 Affected โ€”
8 Fixed โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed qemu-img-8.2.0-11.el9_4.aarch64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1:8.2.0+ds-1
sid Fixed 1:8.2.0+ds-1
forky Fixed 1:8.2.0+ds-1
bullseye Fixed 1:5.2+dfsg-11+deb11u4
bookworm Fixed 1:7.2+dfsg-7+deb12u4
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

Application impact

VendorProductVersionsFixed
qemuqemu{"endExcluding":"8.2.0"}8.2.0

References

CWEs

CWE-416

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.