CVE-2023-40360
published 2023-08-14CVE-2023-40360: QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.39%
31.8th percentile
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:8.0.4+dfsg-2 (forky) | qemu 1:8.0.4+dfsg-2 (forky) |
| qemu | qemu | >= 0 < 1:8.0.4+dfsg-2 | 1:8.0.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:8.0.4+dfsg-2 | 1:8.0.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.28 | 1:4.2-3ubuntu6.28 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.29 | 1:4.2-3ubuntu6.29 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.16 | 1:6.2+dfsg-2ubuntu6.16 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.21 | 1:6.2+dfsg-2ubuntu6.21 |
| qemu | qemu | 8.0.0 – 8.0.4 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
qemu regression
osv·2024-06-06·CVSS 3.2
CVE-2023-2861 [LOW] qemu regression
qemu regression
USN-6567-1 fixed vulnerabilities QEMU. The fix for CVE-2023-2861 was too
restrictive and introduced a behaviour change leading to a regression in
certain environments. This update fixes the problem.
Original advisory details:
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04
OSV
qemu vulnerabilities
osv·2024-01-08·CVSS 3.2
CVE-2020-14394 [LOW] qemu vulnerabilities
qemu vulnerabilities
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-24165)
It was discovered that QEMU incorrectly handled the Intel HD audio device.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affe
GHSA
GHSA-gjhx-wc4x-rwwp: QEMU through 8
ghsa_unreviewed·2023-08-14
CVE-2023-40360 [MEDIUM] CWE-476 GHSA-gjhx-wc4x-rwwp: QEMU through 8
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
OSV
CVE-2023-40360: QEMU through 8
osv·2023-08-14·CVSS 5.5
CVE-2023-40360 [MEDIUM] CVE-2023-40360: QEMU through 8
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
Ubuntu
QEMU regression
vendor_ubuntu·2024-06-06·CVSS 3.2
CVE-2023-2861 [LOW] QEMU regression
Title: QEMU regression
Summary: USN-6567-1 introduced a regression in QEMU.
USN-6567-1 fixed vulnerabilities QEMU. The fix for CVE-2023-2861 was too
restrictive and introduced a behaviour change leading to a regression in
certain environments. This update fixes the problem.
Original advisory details:
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2024-01-08·CVSS 3.2
CVE-2023-1544 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-24165)
It was discovered that QEMU incorrectly handled the Intel HD audio device.
A malicious guest attacker could use this issue to cause QEMU t
Red Hat
QEMU: NVMe: NULL pointer dereference in nvme_directive_receive()
vendor_redhat·2023-08-06·CVSS 5.5
CVE-2023-40360 [MEDIUM] CWE-476 QEMU: NVMe: NULL pointer dereference in nvme_directive_receive()
QEMU: NVMe: NULL pointer dereference in nvme_directive_receive()
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
A flaw was found in the virtual nvme device in QEMU. The nvme_directive_receive() function does not check if an endurance group has been configured (set) prior to testing if flexible data placement is enabled, potentially leading to a NULL pointer dereference issue.
Statement: The `qemu-kvm` packages as shipped with Red Hat Enterprise Linux are not affected by this flaw as they do not include support for NVMe emulation.
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat
Debian
CVE-2023-40360: qemu - QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/...
vendor_debian·2023·CVSS 5.5
CVE-2023-40360 [MEDIUM] CVE-2023-40360: qemu - QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/...
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:8.0.4+dfsg-2)
sid: resolved (fixed in 1:8.0.4+dfsg-2)
trixie: resolved (fixed in 1:8.0.4+dfsg-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/birkelund/qemu/-/commit/6c8f8456cb0b239812dee5211881426496da7b98https://gitlab.com/qemu-project/qemu/-/issues/1815https://security.netapp.com/advisory/ntap-20230915-0004/https://www.qemu.org/docs/master/system/security.htmlhttps://gitlab.com/birkelund/qemu/-/commit/6c8f8456cb0b239812dee5211881426496da7b98https://gitlab.com/qemu-project/qemu/-/issues/1815https://security.netapp.com/advisory/ntap-20230915-0004/https://www.qemu.org/docs/master/system/security.html
2023-08-14
Published