CVE-2023-4135Out-of-bounds Read in Qemu

CWE-125Out-of-bounds Read10 documents7 sources
Severity
6.5MEDIUMNVD
CNA6.0OSV3.2
EPSS
0.0%
top 94.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 4
Latest updateJun 6

Description

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 2.0 | Impact: 4.0

Affected Packages3 packages

NVDqemu/qemu8.0.08.1.0+1
Debianqemu/qemu< 1:8.0.4+dfsg-2+1
Ubuntuqemu/qemu< 1:4.2-3ubuntu6.28+3

Also affects: Fedora 38

Patches

🔴Vulnerability Details

5
OSV
qemu regression2024-06-06
OSV
qemu vulnerabilities2024-01-08
CVEList
Out-of-bounds read information disclosure vulnerability2023-08-04
GHSA
GHSA-fw85-m9vg-m8jv: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU2023-08-04
OSV
CVE-2023-4135: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU2023-08-04

📋Vendor Advisories

4
Ubuntu
QEMU regression2024-06-06
Ubuntu
QEMU vulnerabilities2024-01-08
Red Hat
QEMU: NVMe: out-of-bounds read information disclosure vulnerability2023-08-03
Debian
CVE-2023-4135: qemu - A heap out-of-bounds memory read flaw was found in the virtual nvme device in QE...2023