cbcvebase.
CVE-2023-0330
published 2023-03-06

CVE-2023-0330: A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack…

PriorityP423medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.27%
18.7th percentile
A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianqemu< qemu 1:7.2+dfsg-7+deb12u1 (bookworm)qemu 1:7.2+dfsg-7+deb12u1 (bookworm)
msrccbl2_qemu_6.2.0-22_on_cbl_mariner_2.0
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u31:5.2+dfsg-11+deb11u3
qemuqemu>= 0 < 1:7.2+dfsg-7+deb12u11:7.2+dfsg-7+deb12u1
qemuqemu>= 0 < 1:8.0.2+dfsg-11:8.0.2+dfsg-1
qemuqemu>= 0 < 1:8.0.2+dfsg-11:8.0.2+dfsg-1
qemuqemu>= 0 < 1:4.2-3ubuntu6.271:4.2-3ubuntu6.27
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.111:6.2+dfsg-2ubuntu6.11
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.47+esm32.0.0+dfsg-2ubuntu1.47+esm3
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.51+esm21:2.5+dfsg-5ubuntu10.51+esm2
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.42+esm11:2.11+dfsg-1ubuntu7.42+esm1
qemuqemu>= 7.2.0 < 7.2.37.2.3

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.