296,147
Total vulnerabilities in the database
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Software | From | Fixed in |
---|---|---|
fedoraproject / fedora | 38 | 38.x |
qemu / qemu | 8.1.0-rc2 | 8.1.0-rc2.x |
qemu / qemu | 8.1.0-rc1 | 8.1.0-rc1.x |
qemu / qemu | 8.1.0-rc0 | 8.1.0-rc0.x |
qemu / qemu | 8.0.0 | 8.1.0 |