Description
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0Attack Vector: Local
Complexity: Low
Privileges: High
User Interaction: None
Scope: Changed
Confidentiality: High
Integrity: High
Availability: High
Affected Packages1 packages
🔴Vulnerability Details
2GHSAGHSA-v9pm-v9p5-h96x: A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation↗2024-10-21 ▶ OSVCVE-2024-6519: A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation↗2024-10-21 ▶ 📋Vendor Advisories
3UbuntuQEMU vulnerabilities↗2026-04-09 ▶ Red Hatqemu-kvm: lsi53c895a: use-after-free local privilege escalation vulnerability↗2024-10-10 ▶ DebianCVE-2024-6519: qemu - A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Ad...↗2024 ▶