Total vulnerabilities in the database
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.
Software | From | Fixed in |
---|---|---|
qemu / qemu | - | 7.1.0.x |
fedoraproject / extra_packages_for_enterprise_linux | 8.0 | 8.0.x |
fedoraproject / fedora | 37 | 37.x |
redhat / enterprise_linux | 8.0 | 8.0.x |