cbcvebase.
CVE-2024-3447
published 2024-11-14

CVE-2024-3447: A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer`…

PriorityP425medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.55%
42.8th percentile
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:7.2+dfsg-7+deb12u6 (bookworm)qemu 1:7.2+dfsg-7+deb12u6 (bookworm)
msrcazl3_qemu_8.2.0-14_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-16_on_azure_linux_3.0
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
qemuqemu< 7.2.117.2.11
qemuqemu
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u41:5.2+dfsg-11+deb11u4
qemuqemu>= 0 < 1:7.2+dfsg-7+deb12u61:7.2+dfsg-7+deb12u6
qemuqemu>= 0 < 1:8.2.3+ds-11:8.2.3+ds-1
qemuqemu>= 0 < 1:8.2.3+ds-11:8.2.3+ds-1
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.271:6.2+dfsg-2ubuntu6.27
qemuqemu>= 0 < 1:8.2.2+ds-0ubuntu1.101:8.2.2+ds-0ubuntu1.10
qemuqemu>= 8.0.0 < 8.2.38.2.3
ubuntuqemu

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.