CVE-2023-4135

CVSS V2 None CVSS V3 None
Description
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
Overview
  • CVE ID
  • CVE-2023-4135
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-08-04T13:19:15.760Z
  • Last Modified Date
  • 2024-01-23T01:32:54.867Z
History
Created Old Value New Value Data Type Notes
2024-06-24 19:22:04 Added to TrackCVE