CVE-2023-4135
published 2023-08-04CVE-2023-4135: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before…
PriorityP431medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.41%
33.1th percentile
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:8.0.4+dfsg-2 (forky) | qemu 1:8.0.4+dfsg-2 (forky) |
| fedoraproject | fedora | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:8.0.4+dfsg-2 | 1:8.0.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:8.0.4+dfsg-2 | 1:8.0.4+dfsg-2 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.28 | 1:4.2-3ubuntu6.28 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.29 | 1:4.2-3ubuntu6.29 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.16 | 1:6.2+dfsg-2ubuntu6.16 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.21 | 1:6.2+dfsg-2ubuntu6.21 |
| qemu | qemu | >= 8.0.0 < 8.1.0 | 8.1.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QEMU regression
vendor_ubuntu·2024-06-06·CVSS 3.2
CVE-2023-2861 [LOW] QEMU regression
Title: QEMU regression
Summary: USN-6567-1 introduced a regression in QEMU.
USN-6567-1 fixed vulnerabilities QEMU. The fix for CVE-2023-2861 was too
restrictive and introduced a behaviour change leading to a regression in
certain environments. This update fixes the problem.
Original advisory details:
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2024-01-08·CVSS 3.2
CVE-2023-1544 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-24165)
It was discovered that QEMU incorrectly handled the Intel HD audio device.
A malicious guest attacker could use this issue to cause QEMU t
Red Hat
QEMU: NVMe: out-of-bounds read information disclosure vulnerability
vendor_redhat·2023-08-03·CVSS 6.0
CVE-2023-4135 [MEDIUM] CWE-125 QEMU: NVMe: out-of-bounds read information disclosure vulnerability
QEMU: NVMe: out-of-bounds read information disclosure vulnerability
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Statement: The `qemu-kvm` packages as shipped with Red Hat Enterprise Linux are not affected by this flaw a
Debian
CVE-2023-4135: qemu - A heap out-of-bounds memory read flaw was found in the virtual nvme device in QE...
vendor_debian·2023·CVSS 6.0
CVE-2023-4135 [MEDIUM] CVE-2023-4135: qemu - A heap out-of-bounds memory read flaw was found in the virtual nvme device in QE...
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:8.0.4+dfsg-2)
sid: resolved (fixed in 1:8.0.4+dfsg-2)
trixie: resolved (fixed in 1:8.0.4+dfsg-2)
OSV
qemu regression
osv·2024-06-06·CVSS 3.2
CVE-2023-2861 [LOW] qemu regression
qemu regression
USN-6567-1 fixed vulnerabilities QEMU. The fix for CVE-2023-2861 was too
restrictive and introduced a behaviour change leading to a regression in
certain environments. This update fixes the problem.
Original advisory details:
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04
OSV
qemu vulnerabilities
osv·2024-01-08·CVSS 3.2
CVE-2020-14394 [LOW] qemu vulnerabilities
qemu vulnerabilities
Gaoning Pan and Xingwei Li discovered that QEMU incorrectly handled the
USB xHCI controller device. A privileged guest attacker could possibly use
this issue to cause QEMU to crash, leading to a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2020-14394)
It was discovered that QEMU incorrectly handled the TCG Accelerator. A
local attacker could use this issue to cause QEMU to crash, leading to a
denial of service, or possibly execute arbitrary code and esclate
privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-24165)
It was discovered that QEMU incorrectly handled the Intel HD audio device.
A malicious guest attacker could use this issue to cause QEMU to crash,
leading to a denial of service. This issue only affe
GHSA
GHSA-fw85-m9vg-m8jv: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU
ghsa_unreviewed·2023-08-04
CVE-2023-4135 [MEDIUM] CWE-125 GHSA-fw85-m9vg-m8jv: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
OSV
CVE-2023-4135: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU
osv·2023-08-04·CVSS 6.5
CVE-2023-4135 [MEDIUM] CVE-2023-4135: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-4135https://bugzilla.redhat.com/show_bug.cgi?id=2229101https://security.netapp.com/advisory/ntap-20230915-0012/https://www.zerodayinitiative.com/advisories/ZDI-CAN-21521https://access.redhat.com/security/cve/CVE-2023-4135https://bugzilla.redhat.com/show_bug.cgi?id=2229101https://security.netapp.com/advisory/ntap-20230915-0012/https://www.zerodayinitiative.com/advisories/ZDI-CAN-21521
2023-08-04
Published