VDB
BDU%3A2024-08735
BDU%3A2024-08735
PUBLISHED
CVSS 4.900000095367432 MEDIUM
Уязвимость функции nvme_directive_receive() виртуального устройства NVMe эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
4.900000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., АО «ИВК», Fabrice Bellard | Ubuntu, АЛЬТ СП 10, QEMU |
Timeline
- Oct 30, 2024 CVE Published
- Nov 14, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- https://gitlab.com/qemu-project/qemu/-/issues/1815 url
- https://www.qemu.org/docs/master/system/security.html url
- https://ubuntu.com/security/CVE-2023-40360 url
- https://ubuntu.com/security/notices/USN-6567-1 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2232677 url
- https://cve.basealt.ru/report-02052024-c10f1.html url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://gitlab.com/birkelund/qemu/-/commit/6c8f8456cb0b239812dee5211881426496da7b98 advisory
- https://ubuntu.com/security/notices/USN-6567-1?_gl=1*1q16cn0*_gcl_au*MjAzNjcxNjUyMy4xNzI3NzY0ODgz&_ga=2.68322517.576187372.1730201642-1340999586.1710235970 advisory