cbcvebase.
CVE-2024-7409
published 2024-08-05

CVE-2024-7409: A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a…

PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.03%
60.1th percentile
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:7.2+dfsg-7+deb12u8 (bookworm)qemu 1:7.2+dfsg-7+deb12u8 (bookworm)
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u51:5.2+dfsg-11+deb11u5
qemuqemu>= 0 < 1:7.2+dfsg-7+deb12u81:7.2+dfsg-7+deb12u8
qemuqemu>= 0 < 1:9.0.2+ds-31:9.0.2+ds-3
qemuqemu>= 0 < 1:9.0.2+ds-31:9.0.2+ds-3
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.271:6.2+dfsg-2ubuntu6.27
qemuqemu>= 0 < 1:8.2.2+ds-0ubuntu1.101:8.2.2+ds-0ubuntu1.10
ubuntuqemu

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.