CVE-2024-7730Heap-based Buffer Overflow in Qemu

Severity
7.8HIGHNVD
CNA7.4OSV3.5
EPSS
0.0%
top 88.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 14
Latest updateFeb 20

Description

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds write if the size of the virtio queue element is equal to virtio_snd_pcm_status, which makes the available space for audio data zero.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDqemu/qemu< 9.1.0
Debianqemu/qemu< 1:9.1.0+ds-1+1
Ubuntuqemu/qemu< 1:4.2-3ubuntu6.30+5

🔴Vulnerability Details

4
GHSA
GHSA-pfxg-46gm-p35h: A heap buffer overflow was found in the virtio-snd device in QEMU2024-11-14
OSV
CVE-2024-7730: A heap buffer overflow was found in the virtio-snd device in QEMU2024-11-14
CVEList
Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()2024-11-14
OSV
qemu vulnerabilities2024-11-08

📋Vendor Advisories

5
Red Hat
qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730)2026-02-20
Microsoft
Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()2024-11-12
Ubuntu
QEMU vulnerabilities2024-11-08
Red Hat
qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()2024-07-05
Debian
CVE-2024-7730: qemu - A heap buffer overflow was found in the virtio-snd device in QEMU. When reading ...2024