Total vulnerabilities in the database
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.
Software | From | Fixed in |
---|---|---|
qemu / qemu | 2.12.0 | 4.2.1 |
redhat / enterprise_linux | 7.0 | 7.0.x |
redhat / openstack | 10 | 10.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / openstack | 13 | 13.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
opensuse / leap | 15.1 | 15.1.x |